tune cad detection across all chips

This commit is contained in:
liquidraver
2026-08-29 17:31:39 +02:00
parent d4363775ae
commit 5bf3c577c9
12 changed files with 2203 additions and 1813 deletions
+36 -12
View File
@@ -42,8 +42,8 @@ lowering it means "hear even the faint stuff."** There is no knob that
separates *near* from *far* — only *strong* from *faint* — because the
radio only ever knew signal strength, never distance.
**Semtech's recommended values (AN1200.48: 2129 across all SF/BW for the
SX126x; our base is `SF+13`, which is 21 at SF8) are tuned for a
**Semtech's recommended values (2129 across all SF/BW for the SX126x;
our base is their table, ~2024 at BW125) are tuned for a
receiver** that wants to hear everything down to its sensitivity limit —
i.e. to *catch the faint*. Listen-before-talk on a busy backbone often
wants the opposite: deliberately sit *above* that band so it ignores faint
@@ -51,13 +51,30 @@ contention it would win on capture anyway. So "operating above 29" is not
a misconfiguration here; it is the point.
**Scale sanity, because the register is deceptive.** `cadDetPeak` is a
full 8-bit field (0255), but the *useful* range is only ~1832. The
driver's 40 ceiling is ~11 above the highest value Semtech recommends
anywhere — a near-blind guardrail, not an operating point. And the
LR11xx/LR2021 family's 5668 numbers are a **different chip's correlation
scale**; porting them onto an SX126x makes CAD deaf. If a value feels like
it should be "mid-scale," that instinct is the trap: this scale is
compressed, not linear over 0255.
full 8-bit field (0255), but the *useful* range is only ~1835 on the
SX126x. The driver's 48 ceiling is well above the highest value Semtech
recommends anywhere — a near-blind guardrail, not an operating point. And
the LR11xx/LR2021 family's ~5085 numbers are a **different chip's
correlation scale**; porting them onto an SX126x makes CAD deaf. If a
value feels like it should be "mid-scale," that instinct is the trap: this
scale is compressed, not linear over 0255.
**Bandwidth matters, and it matters unequally.** Semtech's tables are
bracketed by bandwidth, not just SF. On the SX126x the effect is mild —
13 counts per octave — but on the LR11xx it is roughly 12 counts per
octave (at SF7: 52 at BW125, 64 at BW250, 77 at BW500). A bandwidth-blind
base table is therefore a small error on one family and a large one on the
other. This is not theoretical: the LR11xx base table used to be
bandwidth-blind *and* taken from the wrong chip (it was the LR20xx
2-symbol row), reading 56 at SF7 where Semtech says 52. Field T1000-E
companions at SF7/BW62.5 walked eight rungs down to the offset rail
because of it, while an SX1262 in the same room settled at 1.
Below BW125 Semtech declines to give any value, and MeshCore's default
preset is BW62.5 — so our normal operating point is off the end of the
published tables. Both drivers reuse the BW125 row there rather than
extrapolating the trend downward: the curve is noisy empirical PER data,
and the staircase's whole job is to find the local value anyway.
**Why the probes only ever measure the faint side.** A calibration probe
is *skipped* whenever RSSI is more than 7 dB above the noise floor (a
@@ -99,8 +116,10 @@ duty cycle is briefly interrupted and re-armed, within the same
preamble-catch budget philosophy the sniff-mode math already accepts.
Each probe tests one **level**: a signed offset from the chip family's
per-SF base detPeak (SX126x: `SF+13`; LR11xx/LR2021: the 5668 table).
Results accumulate per level:
base detPeak for the current SF, bandwidth and CAD symbol count (all three
from Semtech's LoRa Basics Modem reference tables — SX126x ~1834, LR11xx
~5085, LR2021 its own symbol-indexed table). Results accumulate per
level:
- `probes` — how many CADs ran at this level
- `busy` — raw "activity detected" verdicts
@@ -180,7 +199,12 @@ offset is persisted to flash whenever it steps.
The offset is clamped to **8…+12** levels around the family base — wide
enough that a dense hilltop can settle much less sensitive and a quiet
valley node much more sensitive. The driver additionally clamps the
absolute detPeak (SX126x 1540, LR11xx/LR20xx 4890). That absolute clamp
absolute detPeak (SX126x 1248, LR11xx 40100, LR20xx 4890), and now
*reports* that clamp to the controller, which narrows the offset window to
match. That reporting matters: where base+offset falls outside the clamp,
several offsets collapse onto the same peak, and the staircase reads the
sampling noise between identical configurations as curvature — which is
how a node can random-walk to a rail. That absolute clamp
is a *firmware guardrail*, not a chip limit — `cadDetPeak` is a full
8-bit register (0255) — it simply stops the staircase from wandering
into "CAD never fires" (detPeak too high → LBT effectively off) or "CAD
+1252 -1251
View File
File diff suppressed because it is too large Load Diff
+350 -350
View File
@@ -1,350 +1,350 @@
# Repeater CLI Commands
All commands are sent over USB serial (CDC-ACM). Commands sent remotely over the mesh (non-zero `sender_timestamp`) cannot access USB-only commands.
> The **Room Server** role shares this CLI — the common commands (radio, region, password, advert, gps, etc.) plus `setperm` / `get acl` all apply.
**Sources:**
- `helpers/CommonCLI.cpp` — common commands shared by all roles
- `app/RepeaterMesh.cpp` — repeater-specific commands (`setperm`, `get acl`, `region`, `discover.neighbors`)
- `app/RepeaterRegionCLI.cpp` / `app/RoomServerRegionCLI.cpp` — the `region` sub-CLI
- `app/RepeaterUplink.cpp``get`/`set uplink.*` (ESP32 uplink builds only)
- `app/RoomServerMesh.cpp` — room-server-specific commands (`room.post`)
> **Commands are case-sensitive**, matching Arduino MeshCore. Nothing is lower-cased before matching.
> **Request-tag prefix.** If a command is longer than 4 characters and its **third** character is `|`
> (e.g. `a7|reboot`), the first three characters are stripped before dispatch and echoed back at the
> start of the reply. This is how the phone app correlates replies with requests. It means a command
> whose third character is a literal `|` cannot be sent as-is.
---
## System
| Command | Description |
|---------|-------------|
| `ver` | Firmware version and build date |
| `board` | Board manufacturer name |
| `reboot` | Reboot immediately |
| `start dfu` | nRF52: reboot into the UF2 bootloader for drag-and-drop update. ESP32-S3: reboot into the ROM download mode so esptool can reach the chip |
| `start ota` | ESP32: start WiFi AP + HTTP OTA server. nRF52: reboot into BLE OTA DFU mode |
| `stop ota` | Stop WiFi OTA server (ESP32 only) |
| `clkreboot` | Set clock to a fixed reference time (15 May 2024 8:50pm UTC) then reboot |
| `powersaving` | Not implemented |
---
## Clock
| Command | Description |
|---------|-------------|
| `clock` | Display current UTC time |
| `clock sync` | Sync clock from the sender's timestamp (only advances, cannot go backwards). Arms the 7-day mesh-time-sync suppression window. |
| `time <unix_timestamp>` | Set RTC to a specific Unix timestamp (cannot go backwards). Arms the 7-day mesh-time-sync suppression window. |
---
## Advertisement
| Command | Description |
|---------|-------------|
| `advert` | Send a flood-routed self-advertisement (1500 ms delay) |
| `advert.zerohop` | Send a 0-hop (direct only) self-advertisement |
---
## Neighbors
| Command | Description |
|---------|-------------|
| `neighbors` | Display current neighbor list |
| `neighbor.remove <pubkey_hex>` | Remove a neighbor entry by its public key. A prefix is accepted — the hex is truncated to at most 32 bytes and matched at whatever length you give. **Repeater only in effect:** `RoomServerMesh` does not override `removeNeighbor`, so on a room server this replies `OK` and does nothing. |
| `discover.neighbors` | *(repeater only)* Broadcast a node discovery request to find nearby nodes. Takes no arguments — anything after it replies `Err - discover.neighbors has no options`. Not implemented on room servers. |
---
## Security & Access Control
| Command | Description |
|---------|-------------|
| `password <new_password>` | Set the admin password (**max 15 characters**) |
| `setperm <perms_hex> <pubkey_hex>` | Set ACL permissions for a node (app format: 2-char hex perms first) |
| `setperm <pubkey_hex> <perms_dec>` | Set ACL permissions for a node (Arduino format: pubkey first, decimal perms) |
| `get acl` | *(USB only)* List all ACL entries with permissions and public keys |
> **Password length:** admin and guest passwords are capped at **15 characters** (16-byte storage incl. NUL; same limit as Arduino MeshCore). The login-send path silently truncates anything longer, so a password >15 chars will never authenticate. Applies to `set guest.password` as well.
> **`allow.read.only` is room-server only.** `RoomServerMesh.cpp` is its sole consumer; `RepeaterMesh.cpp` never reads it, so on a repeater the setting silently did nothing. The CLI now only exposes it on `CONFIG_ZEPHCORE_ROLE_ROOM_SERVER` builds — a deliberate divergence from Arduino MeshCore, whose shared CommonCLI offers the knob on every role. The pref itself is unchanged: it stays byte 114 of the on-flash prefs layout, identical to Arduino's, so existing prefs files are unaffected.
> **Guest access differs by role, matching Arduino MeshCore.** On a **repeater**, an empty `guest.password` (the default) means *open* guest access — a blank submitted password logs in as `PERM_ACL_GUEST`, which cannot run CLI commands or read the access list, so it gets login plus status/telemetry only. On a **room server**, an empty `guest.password` *disables* guest login, so a room is never accidentally left open; to run an open room use `set allow.read.only on`, which grants read-only (`PERM_ACL_GUEST`), not post rights. Set a non-empty `guest.password` to require one on either role.
---
## Room Server
| Command | Description |
|---------|-------------|
| `room.post <message>` | Post a message to the shared room as the server itself (system post). Pushed to clients like any other post. |
---
## Region Filtering
Regions control which flood packets the repeater forwards. The region tree is hierarchical; the wildcard `*` region is the root.
| Command | Description |
|---------|-------------|
| `region` | Export the current region map (indented text tree) |
| `region load` | Enter interactive region load mode. Paste indented region lines; send a blank line to commit. Any unindented command (e.g. `reboot`) aborts the load without committing, and then runs |
| `region save` | Save the current region map to persistent storage |
| `region def <token> [...]` | Cursor-walk bulk region builder — define a hierarchy in one line (see below) |
| `region put <name> [<parent>]` | Create a region; default parent is the wildcard root. Flood is **allowed** by default (use `region denyf` to deny) |
| `region remove <name>` | Remove a region (must have no children) |
| `region get <name>` | Show a region's parent and flood-allow flag |
| `region home [<name>]` | Get (no arg) or set the home region |
| `region default [<name>\|<null>]` | Get (no arg), set, or clear (`<null>`) the default flood scope. Originated floods (self-adverts, etc.) are scoped with this region's TransportKey. Auto-creates the region if it doesn't exist and persists immediately |
| `region allowf <name>` | Allow flood packets in a region (clears deny-flood flag) |
| `region denyf <name>` | Deny flood packets in a region (sets deny-flood flag) |
| `region list allowed` | List all regions that allow floods |
| `region list denied` | List all regions that deny floods |
**Region load format:** one region per line, indented with spaces to indicate depth. Append `F` after the name to mark flood-allowed (otherwise flood is denied by default).
**`region def` format:** space-separated tokens; a cursor starts at `*`. Each token is `name` (create child of cursor, advance cursor to it) or `name|jump` / `name,jump` (create child of cursor, then move cursor to the existing region `jump`). Does **not** auto-save — follow with `region save`. Reply is the updated region tree. Example — branched tree: `region def west pnw or pdx|pnw wa sw-wa`. Example — flat list: `region def west|* pnw|* or|* pdx|*`.
---
## Statistics & Logging
| Command | Description |
|---------|-------------|
| `clear stats` | Reset all statistics counters |
| `stats-core` | *(USB only)* Display core mesh statistics |
| `stats-radio` | *(USB only)* Display radio statistics |
| `stats-packets` | *(USB only)* Display packet statistics |
| `log start` | Enable packet logging to file |
| `log stop` | Disable packet logging |
| `log erase` | Erase the log file |
| `log` | *(USB only)* Dump the full log file to USB serial |
| `erase` | *(USB only)* Factory reset: erase the entire LittleFS volume, the BLE-bond NVS, and external QSPI flash, then reboot |
> **`erase` is a true factory reset.** It flattens `lfs_partition` (identity, prefs, ACL,
> region map, logs), `storage_partition` (BLE bonds) and `qspi_storage_partition` where
> present — not just the files under `/lfs/repeater/`. The node comes back with a new
> identity and default prefs. Erasing the volume rather than unlinking files is what makes
> it able to recover a volume another firmware has written into: on nRF52840 the Adafruit
> core's filesystem (used by Arduino MeshCore and Meshtastic) sits at 0xED000, inside our
> `lfs_partition`, and its format scribbles the top 7 blocks of our volume. Switching
> between Arduino-core firmware and ZephCore on nRF52840 needs an erase in **both**
> directions — `tools/formatter` or a full chip erase.
---
## GPS
| Command | Description |
|---------|-------------|
| `gps` | Show GPS status (`on` or `off`) |
| `gps on` | Enable GPS module |
| `gps off` | Disable GPS module |
| `gps setloc` | Update stored latitude/longitude from current GPS fix |
| `gps advert` | Show current location advertising policy |
| `gps advert none` | Do not include location in advertisements |
| `gps advert share` | Include live GPS location in advertisements |
| `gps advert prefs` | Include stored lat/lon from prefs in advertisements |
| `set gps duty <sec>` | GPS duty interval (standby seconds between fixes). `0` = always-on (continuous; streams fresh fixes, can download a full almanac). Floor 10s, cap 604800 (1 week). Persists to flash, applied live. |
| `set gps duty default` | Reset GPS duty to the role default (repeater/room 48h, companion 300s) |
| `set gps diag <0\|1\|on\|off>` | Arm GPS module-configuration diagnostics (see below). Not persisted — clears on reboot |
**GPS configuration diagnostics.** At boot the firmware configures the GNSS module — constellations, AssistNow/EASY, minimum elevation, fix rate — and on modules driven over raw NMEA those commands are sent **blind**: nothing reads the module's reply, so a silently rejected configuration is indistinguishable from a working one. These two commands make that visible.
```
set gps diag 1 # arm it
gps off # power-cycle the module...
gps on # ...which re-runs configuration and records the result
get gps diag # read it back
```
Sample reply:
```
> diag=on cfg=uart age=910s rx=120 mod=URANUS5 sent=12/336B sys=G3/R4/E0/B3/?0
```
- `rx=` NMEA sentences the driver has parsed. **Check this first** — it is the only field that cannot be misread. Non-zero means the module is alive, at the right baud, and talking, so anything still wrong is signal or antenna. Zero means nothing is arriving at all, and no antenna work will help
- `cfg=` which path ran — `uart` (raw PMTK+PCAS+UBX), `api` (driver GNSS API), `blind` (neither available), or `never-run`
- `mod=` module identification, from a CASIC `$GPTXT` version reply or a u-blox `$PUBX` poll response, or `no-reply`. Only an explicit software-version token is accepted as an identity — TXT sentences also carry warnings, and a warning reported as an identity is worse than no answer
- `sent=` commands/bytes written to the module (UART path), or `sys_ret=`/`rate_ret=` return codes (API path)
- `sys=` tracked satellites per constellation from GSV talker IDs: **G**PS / GLONASS (**R**) / Galileo (**E**) / **B**eiDou / other. A constellation that stops reporting for 30 s decays to zero rather than showing a stale count
`sys=` totalling more than `sats=` in `get gps` is expected, not a discrepancy: GSV counts satellites **tracked**, GGA counts satellites **used in the fix solution**.
**`rx=` first, then `mod=`.** `rx=` is the only field that cannot be misread: non-zero means the module is alive, at the right baud and talking, so anything still wrong is signal or antenna; zero means nothing is arriving at all. `mod=` then tells you whether the module *heard* us — everything on this transport is written blind, so a module that hears nothing looks exactly like one that hears everything and ignores it. `mod=no-reply` with `rx=` climbing means the receive direction works but our transmit does not reach it: wiring or pin assignment, not configuration.
**`sent=` proves transmission, not acceptance.** Only `sys=` shows what the module actually did. A module still running its factory or previously saved configuration reports `G` non-zero with the rest at `0`. Note `B0` is expected on u-blox M8 (BeiDou is deliberately disabled — only three major constellations can run concurrently), and `?0` is normal outside Japan (QZSS is regional).
The generic-NMEA path sends three protocols — PMTK (MediaTek), PCAS (CASIC: Quectel L76K/L76KB, Air530Z) and UBX (u-blox) — because a WisBlock-style GPS slot can hold any of them and each family ignores what it does not understand. Related build option: `CONFIG_ZEPHCORE_GPS_NAV_MODE` sets the CASIC navigation dynamic model (`$PCAS11`), defaulting to stationary for repeaters and room servers and automotive otherwise. It is worth setting because that model is stored *in the module* and survives reflashing the host — a slot module that previously lived in another device can arrive stuck in an airborne model that quietly degrades fixes on a fixed site.
Caveats: the `sys=` tally needs `CONFIG_ZEPHCORE_GPS_SAT_DIAG` (default on for repeaters, off for companions to save RAM) — the reply says so when built without it. Only the raw-UART path is re-run on `gps on`; boards with a real GNSS driver (Air530Z, LC76G) keep reporting their boot-time result, because that path goes through `modem_chat_run_script()`, which is safe only at boot. On those boards `E0` is also expected — the Air530Z driver supports GPS/GLONASS/BeiDou but not Galileo, and the firmware falls back automatically.
---
## Sensor Settings
| Command | Description |
|---------|-------------|
| `sensor list [<start_idx>]` | List custom sensor settings (paginated at 134 chars) |
| `sensor get <key>` | Get a custom sensor setting value by key |
| `sensor set <key> <value>` | Set a custom sensor setting value |
---
## Radio (Temporary Override)
| Command | Description |
|---------|-------------|
| `tempradio <freq>,<bw>,<sf>,<cr>,<timeout_mins>` | Apply temporary radio parameters; automatically reverts after `timeout_mins`. Constraints: freq 1502500 MHz, bw 7500 kHz, sf 512, cr 58. Saved prefs are never mutated — concurrent `set` commands and reboots both restore the real saved values. |
---
## Repeater Uplink (ESP32 + `CONFIG_ZEPHCORE_REPEATER_UPLINK`)
These commands configure observer-style WiFi+MQTT packet reporting from repeater role.
All `set uplink.*` changes are saved immediately and only applied after reboot.
| Command | Description |
|---------|-------------|
| `get uplink.status` | Uplink runtime state: enabled flag, WiFi state, MQTT state, reboot-required flag |
| `get uplink.enable` | Uplink enable flag (`on`/`off`) |
| `get uplink.wifi.ssid` | Configured WiFi SSID |
| `get uplink.mqtt.host` | Configured MQTT broker host |
| `get uplink.mqtt.port` | Configured MQTT broker port |
| `get uplink.mqtt.tls` | MQTT TLS mode (`0`/`1`) |
| `get uplink.mqtt.user` | Configured MQTT username |
| `get uplink.mqtt.iata` | Configured IATA/site code used in MQTT topic |
| `set uplink.enable <on\|off>` | Enable or disable repeater uplink *(reboot required)* |
| `set uplink.wifi.ssid <ssid>` | Set WiFi SSID *(reboot required)* |
| `set uplink.wifi.psk <psk>` | Set WiFi password *(reboot required)* |
| `set uplink.mqtt.host <host>` | Set MQTT host *(reboot required)* |
| `set uplink.mqtt.port <port>` | Set MQTT port 165535 *(reboot required)* |
| `set uplink.mqtt.tls <0\|1>` | Set MQTT TLS mode *(reboot required)* |
| `set uplink.mqtt.user <user>` | Set MQTT username *(reboot required)* |
| `set uplink.mqtt.password <pass>` | Set MQTT password *(reboot required)* |
| `set uplink.mqtt.iata <code>` | Set MQTT site code *(reboot required)* |
---
## `get` — Read Configuration
| Command | Returns |
|---------|---------|
| `get name` | Node name |
| `get role` | Firmware role: `repeater` or `room_server` (companion builds report `companion`) |
| `get repeat` | Forwarding enabled: `on` or `off` |
| `get radio` | Radio params as `freq,bw,sf,cr` — the same comma-separated form `set radio` takes, so a reply can be edited and sent straight back |
| `get freq` | Frequency in MHz |
| `get freqerr` | Carrier frequency error measured on received packets: `mean N Hz, min A, max B, K pkts`. **LR2021 only** — other radios answer `not available`. Purely diagnostic; nothing acts on it. **The mean only approximates *this* node's reference error once it is averaged over many different peers** — their individual errors cancel, ours does not — so read `K` and the min/max spread before believing it: a tight spread over a handful of packets is one chatty neighbour, not a population. Small values are the expected answer and mean there is nothing to do; LoRa tolerates carrier error up to roughly a quarter of the bandwidth before sensitivity suffers, so at BW 62.5 kHz a few hundred Hz is noise. If it is kHz-scale the correction is board-dependent: XTAL parts have `SetXoscCpTrim`, but **TCXO parts have no chip-side trim at all** (DS §6.11.4: "If a TCXO is configured, this command has no effect"), leaving only a software offset to the programmed frequency. Values beyond ±200 kHz are discarded by the driver and warn once — the field is decoded from three `GetLoraPacketStatus` bytes that DS rev 2.1 does not document, so implausible readings are evidence the field is not real on that firmware rather than a genuine measurement. Reset by `clear stats`. |
| `get tx` | TX power in dBm |
| `get lat` | Stored latitude |
| `get lon` | Stored longitude |
| `get dutycycle` | Duty cycle as percentage (e.g. "50.0%") |
| `get af` | Raw airtime factor value |
| `get txdelay` | Adaptive TX delay status: contention estimate and flood delay factor |
| `get rxdelay` | *(deprecated)* Always returns "adaptive (rxdelay deprecated)" |
| `get direct.txdelay` | *(deprecated)* Always returns "adaptive (direct.txdelay deprecated)" |
| `get backoff.multiplier` | Per-dupe reactive backoff multiplier |
| `get flood.max` | Max flood retransmit hops |
| `get flood.max.unscoped` | Max retransmit hops for un-scoped floods |
| `get flood.max.advert` | Max retransmit hops for ADVERT floods |
| `get flood.advert.interval` | Flood advertisement interval in hours |
| `get advert.interval` | Local advertisement interval in minutes |
| `get allow.read.only` | *(room server only)* Whether read-only clients are allowed |
| `get guest.password` | Guest access password |
| `get owner.info` | Owner/contact info (pipes `\|` display as newlines) |
| `get int.thresh` | Interference threshold |
| `get leds` | LED master switch: `on` or `off` |
| `get buzzer` | *(room server only)* Buzzer/vibration mode as `<n> (<name>)`: `0 (silent)`, `1 (sound+vib)`, `2 (vibrate)`, `3 (sound)`. Compiled out on repeater builds (`#ifndef ZEPHCORE_REPEATER`) — a repeater answers `unknown config: buzzer`. |
| `get agc.reset.interval` | Removed — replies `Removed - Automatic AGC reset is on`. Periodic AGC recalibration was deleted (it reset the noise floor to its unseeded sentinel on every fire). Use `set rxduty` to cut RX current. |
| `get multi.acks` | Extra ACK transmit count (`0` or `1`) |
| `get path.hash.mode` | Path hashing algorithm: `0`, `1`, or `2` |
| `get loop.detect` | Loop detection level: `off`, `minimal`, `moderate`, or `strict` |
| `get radio.rxgain` | RX gain boost: `on` or `off` |
| `get radio.fem.rxgain` | External FEM's LNA in the RX path: `on` (through the LNA) or `off` (bypassed). Default `on` |
| `get rxduty` | RX duty cycle mode: `0` or `1` |
| `get display.rotate` | Panel 180-degree rotation: `0` or `1`. Reports the **live panel state**, not the stored byte — the two differ only when a rotation was refused, which is the case worth seeing. Boards whose panel cannot rotate reply `unsupported (panel cannot rotate)` |
| `get input.rotate` | Joystick/D-pad axis swap: `0` or `1` |
| `get gps duty` | Now-effective GPS duty interval in seconds (`always on (0)` when continuous) |
| `get gps diag` | What the last GPS module-configuration attempt did — which path ran, bytes sent, and tracked satellites per constellation. See **GPS configuration diagnostics** in the GPS section for the field reference |
| `get meshtimesync` | Mesh time-sync state + live dry-run: on/off, eligible voter count, votes for/against, consensus skew and radius, would-be verdict (`ok`/`in-band`/`step±N`/`abstain (reason)`/`hold (reason)`; a recent clock set — manual or GPS — shows as `hold (suppressed)`, and a backward step a forward-only role would refuse is annotated `(skipped: forward-only)`), step counters, suppression countdown, and a per-sender evidence table (`prefix hops count skew E`, `E` = counted toward the verdict above). Entries that count print first, so a size-capped reply never hides the ones that explain the summary; if the table doesn't fully fit, a trailing `+N more` shows how many were left out. Sensing runs even while off, so this works as a dry-run before enabling. Over remote admin the reply is truncated to the packet size (summary always fits); the full table needs the USB CLI. |
| `get probe.interval` | Seconds between periodic radio measurements (noise-floor sample + CAD probe). 0 = CAD probing off |
| `get dc.restarts` | Duty-cycle re-arm counter — RxTimeout re-arms **plus** parked-RX watchdog recoveries, sharing one total. **Read it as a rate: divide by uptime.** A bare count is not interpretable, and the two sources it merges cost very differently. An RxTimeout re-arm is ~7 ms of deaf time (the `Calibrate(ALL)` gap in the driver's `restart_rx`) after which the chip returns to duty cycle immediately — packets, not power. A watchdog recovery means the chip sat parked in *full RX* for one to two watchdog periods (`2·(preamble+8)` symbols, floored at 250 ms) — power, not packets, since parked RX still receives. The counter cannot tell you which, so read the worst case. **Measured normal: ~250/hr on a high site at SF8/BW 62.5** (one every ~14 s), where the worst case — every event a park — costs about 3.5% of the duty cycle's savings. Nothing to act on below roughly **2000/hr**; above that the parked-RX share starts eating a meaningful fraction of the saving and it becomes worth splitting the counter to find out. A high rate means the preamble detector is tripping without a decodable packet following, which on an elevated site is usually distant marginal traffic rather than interference — cross-check `get cad.stats`, whose adaptive detPeak offset rises independently in a genuinely busy RF environment. Reset by `clear stats`. |
| `get cad` | Always `on` — ZephCore performs CAD/LBT unconditionally and has no enable knob. Kept as a boolean reply for Arduino MeshCore app compatibility; the real status lives in `get cad.stats`. |
| `get cad.stats` | Adaptive-CAD status: header (`a` auto on/off, `o` operating detPeak offset, `pk` absolute peak with family base, `sp` noise-floor RSSI burst quality as `mean-spread-dB/zero-spread-%` (plus `(burst-count rN/bN/aN)` on the local USB console, omitted over the air to protect the 161 B reply budget, where `r` is completed RSSI reads, `b` reads the chip refused as busy, and `a` bursts abandoned because of one — on a healthy radio `b`/`a` stay at 0, and a large `a` against a near-zero burst count is the signature of a sampler being refused rather than one losing the odd read) — a non-zero mean proves the 8 reads are independent however high the share climbs; only mean `0.0` with a high share indicts the sampler. See `ADAPTIVE_CAD.md`. `bc` busy cap), then a 3-rung window around the operating offset (`*` marks it) with probe/busy/fp/tp counts and false-positive rate — the three levels the knee controller reads. Probing runs even while `cad.auto` is off (dry-run), so this is the observation tool for picking a site-appropriate detPeak. See `ADAPTIVE_CAD.md`. Not available on SX127x boards (no hardware CAD). |
| `get extra.sf` | LR2021 side detectors: the extra spreading factors currently received alongside `sf`, comma-separated (bare, no `> ` prefix), or `No extra SF configured`. Reflects the saved prefs, not what the chip accepted — if the set became invalid after an `sf`/`bw` change it is reported here but was refused at boot (a `WRN` line says so). |
| `get adc.multiplier` | Battery voltage ADC calibration multiplier |
| `get bootloader.ver` | Bootloader version string |
| `get public.key` | Node's public key as hex. **Not** USB-only — it is answerable over remote admin, matching Arduino MeshCore. A public key is broadcast in every advert, so there is nothing to gate. |
| `get prv.key` | *(USB only)* Node's private key as hex — the 128-char expanded form, the same one `set prv.key` takes |
---
## `set` — Write Configuration
Changes are persisted immediately unless noted. Some require a reboot.
| Command | Constraints | Description |
|---------|-------------|-------------|
| `set name <name>` | No `[ ] \ : , ? *` | Set node name |
| `set repeat <on\|off>` | | Enable or disable packet forwarding |
| `set radio <freq>,<bw>,<sf>,<cr>` | freq 1502500, bw 7500, sf 512, cr 58 | **Comma-separated**, not space-separated — spaces parse as a single argument and the command is rejected. Set radio params *(reboot required)* |
| `set freq <mhz>` | 1502500 *(USB only)* | Set frequency alone *(reboot required)* |
| `set tx <dbm>` | 9 to board max (default 30) | Set TX power |
| `set lat <latitude>` | | Set stored latitude |
| `set lon <longitude>` | | Set stored longitude |
| `set dutycycle <pct>` | 1100 | Set duty cycle percentage (converted to airtime factor internally) |
| `set af <value>` | float | Set raw airtime factor directly |
| `set txdelay <value>` | | Accepted for prefs compatibility — **ignored** (txdelay is adaptive) |
| `set rxdelay <value>` | | Accepted for prefs compatibility — **ignored** (rxdelay is adaptive) |
| `set direct.txdelay <value>` | | Accepted for prefs compatibility — **ignored** (direct.txdelay is adaptive) |
| `set backoff.multiplier <m>` | 0.02.0 | Per-dupe reactive backoff multiplier (0 = disable reactive backoff) |
| `set flood.max <count>` | 064 | Maximum flood retransmit hops |
| `set flood.max.unscoped <count>` | 064 | Hop limit for un-scoped floods only (default 64 = same as flood.max); scoped/transport floods still use flood.max |
| `set flood.max.advert <count>` | 064 | Hop limit for ADVERT floods only (default 8); curbs advert churn independent of flood.max |
| `set flood.advert.interval <hours>` | `0` (off) or 3168 | How often the repeater floods its own advertisement. `0` disables periodic flood adverts. |
| `set advert.interval <mins>` | `0` (off) or min240 | How often the repeater sends local (zero-hop) advertisements. `0` — the default — disables them. Stored halved (the pref holds minutes/2), so odd values round down. |
| `set allow.read.only <on\|off>` | | *(room server only)* Allow or deny read-only client connections |
| `set guest.password <pwd>` | | Set guest access password |
| `set owner.info <text>` | Use `\|` for newlines | Owner/contact information |
| `set int.thresh <value>` | | Interference detection threshold |
| `set buzzer <0\|1\|2\|3>` | or `off` / `on` / `vibrate` / `sound` | *(room server only)* `0`/`off` silent, `1`/`on` sound + vibration, `2`/`vibrate` vibration only, `3`/`sound` sound only. Modes 2 and 3 need a vibration motor; without one the node replies `Error: no vibration motor on this board - use 0 or 1`. Applied live and persisted. Compiled out on repeater builds. |
| `set leds <on\|off\|1\|0>` | default **on** | Master switch for every LED on the node, applied live and persisted: heartbeat, unread-message and LoRa TX-activity LEDs, plus the message and shutdown flashes. Works on every role, including headless repeaters where the TX LED is the only one that ever lights. Does **not** cover the display backlight, which is a separate UI brightness setting. |
| `set agc.reset.interval <ms>` | Accepted, ignored | Removed — replies `Removed - Automatic AGC reset is on`. The prefs byte is still read and written so the on-flash layout stays byte-exact, but nothing acts on it. |
| `set multi.acks <0\|1>` | | Enable extra ACK transmits |
| `set path.hash.mode <mode>` | 0, 1, or 2 | Path hashing algorithm |
| `set loop.detect <mode>` | `off`, `minimal`, `moderate`, `strict` | Loop detection sensitivity |
| `set radio.rxgain <0\|1\|on\|off>` | | RX gain boost, applied live. Replies `Error: unsupported` on radios without RX boost (SX127x); the pref is still saved. |
| `set radio.fem.rxgain <0\|1\|on\|off>` | default **1** | Routes receive through the external FEM's LNA (`1`) or around it via the FEM's bypass path (`0`), applied live. Sensitivity for battery life — `0` costs roughly 17 dB and saves the LNA's supply current. Transmit, and the driver's idle/sleep gating of the FEM, are unaffected either way. Supported only where the FEM's receive path is software-selectable and that select line is wired to the radio node as `lna-bypass-gpios` — today the three KCT8103L boards, `heltec_t096`, `heltec_wireless_tracker_v2` and `heltec_wifi_lora32_v43`. Every other board reports `Error: unsupported`: `heltec_wifi_lora32_v4`'s GC1109 has no receive-path select (its CPS is don't-care in RX, same as MeshCore); `station_g2`, `gat562_30s`, `ikoka_nano_30dbm` and `promicro_sx1262` have only the DIO2/TXEN/RXEN transmit-receive switch; `rak3401_1watt`'s SKY66122 is enabled by a standalone always-on regulator outside the radio node; and non-SX126x radios (LR1110, LR2021, SX127x) never implement it. The pref is still saved when unsupported. **Do not expect the FEM's chip-enable to be the knob** — deasserting `antenna-enable-gpios` in RX shuts the part down and takes the through path with it (~69 dB measured on a V4.3), which is what 1.17.2 did before this moved to `lna-bypass-gpios`. |
| `set rxduty <0\|1\|on\|off>` | | RX duty cycle mode *(reboot required)*. Window timing auto-sized per SF/BW/preamble from the SX126x datasheet constraints (boot log line `rxduty:` shows the result). Zero-loss guarantee assumes senders on preamble-32 firmware (current MeshCore at SF≤8); legacy preamble-16 senders are only caught ~50% worst-phase — keep off until the local mesh has converted. Presets with 16-symbol preambles (SF≥9) fall back to continuous RX automatically. |
| `set display.rotate <0\|1\|on\|off>` | default **0** | Rotate the display 180 degrees, for cases and upgrade kits that mount the screen upside down (e.g. the Meshnology N37E for the Wio Tracker L1). Applied live — the driver flips the panel's `SEGMENT_MAP` and `COM_OUTPUT_SCAN`, two bytes on the wire, and the next frame comes out rotated with no redraw and no per-frame cost. **Only full-height SSD1306 and SH1106 panels support this** (`rak4631`, `gat562_30s`, `heltec_wifi_lora32_v4`/`v43`, `lilygo_t3s3`, `station_g2`, `wio_tracker_l1`); every other panel replies `Error: this panel cannot rotate` and the pref is **not** saved, so a stored value can never disagree with what the screen shows. `lilygo_timpulse_plus` is excluded despite being an SSD1306: its 64x32 glass is windowed into a 128x64 controller at `page-offset 4`, and the COM-scan reversal flips the controller's whole range, which would move the image off the bonded region. E-paper (SSD16xx) is excluded on purpose: its driver accepts a 180-degree orientation but implements it by flipping the RAM entry mode only, which reverses byte order without reversing bit order inside each byte — it would report success and render wrong. |
| `set input.rotate <0\|1\|on\|off>` | default **0** | Swap the joystick/D-pad axes — up/down and left/right — to match an upside-down mount. Applied live. Deliberately **separate** from `display.rotate`: a case can flip the screen without moving the stick, and boards whose panel cannot rotate can still need the axis swap. Works on every board with directional input, in both the joystick UI and the button UI (where it swaps page-prev/page-next). Non-directional keys, tap codes and long-press gestures are unaffected. |
| `set adc.multiplier <mult>` | `0` (use board default) or 10030000 | Battery voltage ADC calibration multiplier, set directly. Rejects non-numeric input, NaN/inf and negatives. |
| `set adc.multiplier target <mv>` | 30004400 mV | Calibrate against a voltage you measured with a multimeter: rescales the current multiplier so the ADC reads `<mv>`. Replies with the old and new multiplier plus the before/after reading. `Error: no ADC reading on this board` if the board has no battery ADC. |
| `set adc.multiplier full` | board must be fully charged | Same calibration, but against the board's battery-curve 100% point instead of a hand-measured value. Only meaningful on a full charge. |
| `set meshtimesync <on\|off>` | default **off** | Mesh time sync: automatically correct this node's clock from the consensus of Ed25519-signed advert timestamps heard on the mesh. Steps at most ±1 h per step, one step per 6 h; abstains without a quorum (default 6) of tenured agreeing senders; never overrides a clock set in the last 7 days, whether from GPS (re-armed on every fix) or a manual set. See `MESHTIMESYNC.md`. |
| `set cad.auto <on\|off>` | default **on** | Adaptive CAD: let the staircase controller move the operating detPeak offset based on probe statistics. On by default (repeaters and companions); at the default 15 s probe interval it responds to environment change in ~12 h. Turn off to observe/hand-tune via `get cad.stats` + `set cad.offset`. See `ADAPTIVE_CAD.md`. |
| `set cad.offset <n>` | 8 to 12, default 0 | Operating detPeak offset from the chip family's per-SF base (SX126x: SF+13; LR11xx/LR20xx: 5668 table). Negative = more sensitive LBT (catches weaker signals, risks false busy), positive = less sensitive. Wide range so dense hilltops / quiet valleys can settle far from base. The per-family absolute clamp in the driver (SX126x 1540, LR 4890) is a firmware guardrail against a CAD that never/always fires, not a chip limit (`cadDetPeak` is a full `uint8_t`). Applied live; the auto staircase may move it later if `cad.auto` is on. |
| `set probe.interval <sec>` | 0 (off) or 10255, default **15** | Seconds between periodic radio measurements. ONE reading serves both: the noise-floor RSSI sample (median of 8) and the CAD calibration probe, which consumes that same reading rather than measuring separately — so this is also the noise-floor sampling rate, and it sets how often an idle repeater wakes. Default 15 s → ~12 h CAD staircase response; the floor EMA warms up over 8 samples (~2 min) and its unguarded bypass runs every 16th (~4 min). Longer = fewer wakes, slower to track a changing RF environment. 0 disables CAD probing entirely (also freezes auto adaptation); the floor sampler then falls back to its build-time default. |
| `set cad.busycap <pct>` | 0 (off) or 1090, default **25** | Airtime-protection cap: the max percentage of TX attempts the node will let CAD defer before the staircase backs off to a less sensitive detPeak — counting **real** traffic, not just false positives. On a congested hilltop most busy verdicts are distant traffic won on capture anyway, so deferring for all of it starves the node's own airtime. Self-targeting: a quiet node's busy rate never reaches the cap. Shown as `bc:` in `get cad.stats`. 0 disables the cap (pure knee-seeking). |
| `set cad.reset` | | Clear the accumulated per-level CAD probe statistics (RAM only; also cleared automatically on any radio parameter change). |
| `set extra.sf <sf> [sf] [sf]` | up to 3 SFs, `0`/`off` clears | **LR2021 only** (`Error: unsupported` elsewhere) — LoRa *side detectors*: demodulate up to three extra spreading factors concurrently with `sf`, on the same bandwidth, so one repeater can serve several SF communities. Which SF a packet arrived on is a chip-side readout, not a guess. Chip constraints, enforced in the driver and reported as `Error: unsupported or invalid extra SF config`: every extra SF must be **greater** than `sf`, all distinct, highestlowest ≤ 4, and at BW ≥ 500 kHz at most 2 (only 1 when `sf` ≥ 10). **Receive only, and the bridge it creates is one-way.** TX always uses the single configured `sf`, and all detectors share one bandwidth, so this is multi-SF, not multi-channel. A node with `sf 7` + `extra.sf 8` hears SF8 traffic and *does* forward it — but the forward goes out at SF7, so traffic moves SF8 -> SF7 only and nothing comes back. An SF8 node's direct messages are delivered while its ACKs never arrive, so it retries to its limit every time; adverts and one-way flood traffic propagate fine. Because every extra SF must be **greater** than `sf`, the main SF is always the lowest in the set and TX always uses it — so the bridge direction is fixed at high-SF-in / low-SF-out and **cannot be reversed**. Two nodes back to back both point the same way; there is no configuration that carries SF7 -> SF8. Treat it as a collector for slower-SF stragglers, not as a link between two SF islands. Applied live and restored on every RX entry. **Interaction with CAD:** the chip's SF constraint for CAD is the inverse of the one for RX, so the driver switches side detectors off for each LBT CAD and back on when RX re-arms — two extra SPI commands per TX, no configuration required. Persisted; a set that no longer fits after an `sf`/`bw` change is refused at boot and logged. |
| `set prv.key <hex>` | **128-char hex** (64-byte expanded Ed25519 key) | Replace private key; derive new identity *(reboot to apply)*. The length must be exact — `fromHex` rejects anything else with `Error, bad key`. `get prv.key` returns the same 128-char form. Not USB-gated. |
---
## Notes
- **USB-only commands**`get acl`, `get prv.key`, `set freq`, `log` (dump), `stats-packets`, `stats-radio`, `stats-core`, `erase` — are blocked when the command arrives over the mesh (remote admin). These are the only ones gated on `sender_timestamp == 0`; `get public.key` and `set prv.key` are **not** among them.
- **Adaptive contention window**`txdelay`, `rxdelay`, and `direct.txdelay` are accepted and stored for Arduino prefs compatibility but have no effect. Use `get txdelay` to inspect the current adaptive state and `set backoff.multiplier` to tune reactive backoff.
- **Region load mode** — after `region load`, every line received is parsed as a region entry until a blank line is sent. The loaded map is only committed to the live region tree at that point; use `region save` to persist it. Region rows must be indented by at least one space, so an **unindented line that starts with a name character aborts the mode and is executed as a normal command** — the escape hatch if a `region load` is started by accident or a client dies mid-transfer. An abort discards the partial map, leaving the live region tree untouched. The exported wildcard header line `*` stays unindented and is ignored as before, so pasting the output of `region` still loads cleanly.
- **Reboot delay**`start dfu`, `start ota` (nRF52 BLE-DFU path only), `reboot`, `clkreboot` and `erase` defer the reset by **2 seconds** so the reply can be transmitted over LoRa first. On a companion the handler then keeps deferring in 20 ms steps until the BLE/USB transport has drained, up to a further 3 s grace. On ESP32 `start ota` starts a WiFi AP + HTTP server and does **not** reboot.
# Repeater CLI Commands
All commands are sent over USB serial (CDC-ACM). Commands sent remotely over the mesh (non-zero `sender_timestamp`) cannot access USB-only commands.
> The **Room Server** role shares this CLI — the common commands (radio, region, password, advert, gps, etc.) plus `setperm` / `get acl` all apply.
**Sources:**
- `helpers/CommonCLI.cpp` — common commands shared by all roles
- `app/RepeaterMesh.cpp` — repeater-specific commands (`setperm`, `get acl`, `region`, `discover.neighbors`)
- `app/RepeaterRegionCLI.cpp` / `app/RoomServerRegionCLI.cpp` — the `region` sub-CLI
- `app/RepeaterUplink.cpp``get`/`set uplink.*` (ESP32 uplink builds only)
- `app/RoomServerMesh.cpp` — room-server-specific commands (`room.post`)
> **Commands are case-sensitive**, matching Arduino MeshCore. Nothing is lower-cased before matching.
> **Request-tag prefix.** If a command is longer than 4 characters and its **third** character is `|`
> (e.g. `a7|reboot`), the first three characters are stripped before dispatch and echoed back at the
> start of the reply. This is how the phone app correlates replies with requests. It means a command
> whose third character is a literal `|` cannot be sent as-is.
---
## System
| Command | Description |
|---------|-------------|
| `ver` | Firmware version and build date |
| `board` | Board manufacturer name |
| `reboot` | Reboot immediately |
| `start dfu` | nRF52: reboot into the UF2 bootloader for drag-and-drop update. ESP32-S3: reboot into the ROM download mode so esptool can reach the chip |
| `start ota` | ESP32: start WiFi AP + HTTP OTA server. nRF52: reboot into BLE OTA DFU mode |
| `stop ota` | Stop WiFi OTA server (ESP32 only) |
| `clkreboot` | Set clock to a fixed reference time (15 May 2024 8:50pm UTC) then reboot |
| `powersaving` | Not implemented |
---
## Clock
| Command | Description |
|---------|-------------|
| `clock` | Display current UTC time |
| `clock sync` | Sync clock from the sender's timestamp (only advances, cannot go backwards). Arms the 7-day mesh-time-sync suppression window. |
| `time <unix_timestamp>` | Set RTC to a specific Unix timestamp (cannot go backwards). Arms the 7-day mesh-time-sync suppression window. |
---
## Advertisement
| Command | Description |
|---------|-------------|
| `advert` | Send a flood-routed self-advertisement (1500 ms delay) |
| `advert.zerohop` | Send a 0-hop (direct only) self-advertisement |
---
## Neighbors
| Command | Description |
|---------|-------------|
| `neighbors` | Display current neighbor list |
| `neighbor.remove <pubkey_hex>` | Remove a neighbor entry by its public key. A prefix is accepted — the hex is truncated to at most 32 bytes and matched at whatever length you give. **Repeater only in effect:** `RoomServerMesh` does not override `removeNeighbor`, so on a room server this replies `OK` and does nothing. |
| `discover.neighbors` | *(repeater only)* Broadcast a node discovery request to find nearby nodes. Takes no arguments — anything after it replies `Err - discover.neighbors has no options`. Not implemented on room servers. |
---
## Security & Access Control
| Command | Description |
|---------|-------------|
| `password <new_password>` | Set the admin password (**max 15 characters**) |
| `setperm <perms_hex> <pubkey_hex>` | Set ACL permissions for a node (app format: 2-char hex perms first) |
| `setperm <pubkey_hex> <perms_dec>` | Set ACL permissions for a node (Arduino format: pubkey first, decimal perms) |
| `get acl` | *(USB only)* List all ACL entries with permissions and public keys |
> **Password length:** admin and guest passwords are capped at **15 characters** (16-byte storage incl. NUL; same limit as Arduino MeshCore). The login-send path silently truncates anything longer, so a password >15 chars will never authenticate. Applies to `set guest.password` as well.
> **`allow.read.only` is room-server only.** `RoomServerMesh.cpp` is its sole consumer; `RepeaterMesh.cpp` never reads it, so on a repeater the setting silently did nothing. The CLI now only exposes it on `CONFIG_ZEPHCORE_ROLE_ROOM_SERVER` builds — a deliberate divergence from Arduino MeshCore, whose shared CommonCLI offers the knob on every role. The pref itself is unchanged: it stays byte 114 of the on-flash prefs layout, identical to Arduino's, so existing prefs files are unaffected.
> **Guest access differs by role, matching Arduino MeshCore.** On a **repeater**, an empty `guest.password` (the default) means *open* guest access — a blank submitted password logs in as `PERM_ACL_GUEST`, which cannot run CLI commands or read the access list, so it gets login plus status/telemetry only. On a **room server**, an empty `guest.password` *disables* guest login, so a room is never accidentally left open; to run an open room use `set allow.read.only on`, which grants read-only (`PERM_ACL_GUEST`), not post rights. Set a non-empty `guest.password` to require one on either role.
---
## Room Server
| Command | Description |
|---------|-------------|
| `room.post <message>` | Post a message to the shared room as the server itself (system post). Pushed to clients like any other post. |
---
## Region Filtering
Regions control which flood packets the repeater forwards. The region tree is hierarchical; the wildcard `*` region is the root.
| Command | Description |
|---------|-------------|
| `region` | Export the current region map (indented text tree) |
| `region load` | Enter interactive region load mode. Paste indented region lines; send a blank line to commit. Any unindented command (e.g. `reboot`) aborts the load without committing, and then runs |
| `region save` | Save the current region map to persistent storage |
| `region def <token> [...]` | Cursor-walk bulk region builder — define a hierarchy in one line (see below) |
| `region put <name> [<parent>]` | Create a region; default parent is the wildcard root. Flood is **allowed** by default (use `region denyf` to deny) |
| `region remove <name>` | Remove a region (must have no children) |
| `region get <name>` | Show a region's parent and flood-allow flag |
| `region home [<name>]` | Get (no arg) or set the home region |
| `region default [<name>\|<null>]` | Get (no arg), set, or clear (`<null>`) the default flood scope. Originated floods (self-adverts, etc.) are scoped with this region's TransportKey. Auto-creates the region if it doesn't exist and persists immediately |
| `region allowf <name>` | Allow flood packets in a region (clears deny-flood flag) |
| `region denyf <name>` | Deny flood packets in a region (sets deny-flood flag) |
| `region list allowed` | List all regions that allow floods |
| `region list denied` | List all regions that deny floods |
**Region load format:** one region per line, indented with spaces to indicate depth. Append `F` after the name to mark flood-allowed (otherwise flood is denied by default).
**`region def` format:** space-separated tokens; a cursor starts at `*`. Each token is `name` (create child of cursor, advance cursor to it) or `name|jump` / `name,jump` (create child of cursor, then move cursor to the existing region `jump`). Does **not** auto-save — follow with `region save`. Reply is the updated region tree. Example — branched tree: `region def west pnw or pdx|pnw wa sw-wa`. Example — flat list: `region def west|* pnw|* or|* pdx|*`.
---
## Statistics & Logging
| Command | Description |
|---------|-------------|
| `clear stats` | Reset all statistics counters |
| `stats-core` | *(USB only)* Display core mesh statistics |
| `stats-radio` | *(USB only)* Display radio statistics |
| `stats-packets` | *(USB only)* Display packet statistics |
| `log start` | Enable packet logging to file |
| `log stop` | Disable packet logging |
| `log erase` | Erase the log file |
| `log` | *(USB only)* Dump the full log file to USB serial |
| `erase` | *(USB only)* Factory reset: erase the entire LittleFS volume, the BLE-bond NVS, and external QSPI flash, then reboot |
> **`erase` is a true factory reset.** It flattens `lfs_partition` (identity, prefs, ACL,
> region map, logs), `storage_partition` (BLE bonds) and `qspi_storage_partition` where
> present — not just the files under `/lfs/repeater/`. The node comes back with a new
> identity and default prefs. Erasing the volume rather than unlinking files is what makes
> it able to recover a volume another firmware has written into: on nRF52840 the Adafruit
> core's filesystem (used by Arduino MeshCore and Meshtastic) sits at 0xED000, inside our
> `lfs_partition`, and its format scribbles the top 7 blocks of our volume. Switching
> between Arduino-core firmware and ZephCore on nRF52840 needs an erase in **both**
> directions — `tools/formatter` or a full chip erase.
---
## GPS
| Command | Description |
|---------|-------------|
| `gps` | Show GPS status (`on` or `off`) |
| `gps on` | Enable GPS module |
| `gps off` | Disable GPS module |
| `gps setloc` | Update stored latitude/longitude from current GPS fix |
| `gps advert` | Show current location advertising policy |
| `gps advert none` | Do not include location in advertisements |
| `gps advert share` | Include live GPS location in advertisements |
| `gps advert prefs` | Include stored lat/lon from prefs in advertisements |
| `set gps duty <sec>` | GPS duty interval (standby seconds between fixes). `0` = always-on (continuous; streams fresh fixes, can download a full almanac). Floor 10s, cap 604800 (1 week). Persists to flash, applied live. |
| `set gps duty default` | Reset GPS duty to the role default (repeater/room 48h, companion 300s) |
| `set gps diag <0\|1\|on\|off>` | Arm GPS module-configuration diagnostics (see below). Not persisted — clears on reboot |
**GPS configuration diagnostics.** At boot the firmware configures the GNSS module — constellations, AssistNow/EASY, minimum elevation, fix rate — and on modules driven over raw NMEA those commands are sent **blind**: nothing reads the module's reply, so a silently rejected configuration is indistinguishable from a working one. These two commands make that visible.
```
set gps diag 1 # arm it
gps off # power-cycle the module...
gps on # ...which re-runs configuration and records the result
get gps diag # read it back
```
Sample reply:
```
> diag=on cfg=uart age=910s rx=120 mod=URANUS5 sent=12/336B sys=G3/R4/E0/B3/?0
```
- `rx=` NMEA sentences the driver has parsed. **Check this first** — it is the only field that cannot be misread. Non-zero means the module is alive, at the right baud, and talking, so anything still wrong is signal or antenna. Zero means nothing is arriving at all, and no antenna work will help
- `cfg=` which path ran — `uart` (raw PMTK+PCAS+UBX), `api` (driver GNSS API), `blind` (neither available), or `never-run`
- `mod=` module identification, from a CASIC `$GPTXT` version reply or a u-blox `$PUBX` poll response, or `no-reply`. Only an explicit software-version token is accepted as an identity — TXT sentences also carry warnings, and a warning reported as an identity is worse than no answer
- `sent=` commands/bytes written to the module (UART path), or `sys_ret=`/`rate_ret=` return codes (API path)
- `sys=` tracked satellites per constellation from GSV talker IDs: **G**PS / GLONASS (**R**) / Galileo (**E**) / **B**eiDou / other. A constellation that stops reporting for 30 s decays to zero rather than showing a stale count
`sys=` totalling more than `sats=` in `get gps` is expected, not a discrepancy: GSV counts satellites **tracked**, GGA counts satellites **used in the fix solution**.
**`rx=` first, then `mod=`.** `rx=` is the only field that cannot be misread: non-zero means the module is alive, at the right baud and talking, so anything still wrong is signal or antenna; zero means nothing is arriving at all. `mod=` then tells you whether the module *heard* us — everything on this transport is written blind, so a module that hears nothing looks exactly like one that hears everything and ignores it. `mod=no-reply` with `rx=` climbing means the receive direction works but our transmit does not reach it: wiring or pin assignment, not configuration.
**`sent=` proves transmission, not acceptance.** Only `sys=` shows what the module actually did. A module still running its factory or previously saved configuration reports `G` non-zero with the rest at `0`. Note `B0` is expected on u-blox M8 (BeiDou is deliberately disabled — only three major constellations can run concurrently), and `?0` is normal outside Japan (QZSS is regional).
The generic-NMEA path sends three protocols — PMTK (MediaTek), PCAS (CASIC: Quectel L76K/L76KB, Air530Z) and UBX (u-blox) — because a WisBlock-style GPS slot can hold any of them and each family ignores what it does not understand. Related build option: `CONFIG_ZEPHCORE_GPS_NAV_MODE` sets the CASIC navigation dynamic model (`$PCAS11`), defaulting to stationary for repeaters and room servers and automotive otherwise. It is worth setting because that model is stored *in the module* and survives reflashing the host — a slot module that previously lived in another device can arrive stuck in an airborne model that quietly degrades fixes on a fixed site.
Caveats: the `sys=` tally needs `CONFIG_ZEPHCORE_GPS_SAT_DIAG` (default on for repeaters, off for companions to save RAM) — the reply says so when built without it. Only the raw-UART path is re-run on `gps on`; boards with a real GNSS driver (Air530Z, LC76G) keep reporting their boot-time result, because that path goes through `modem_chat_run_script()`, which is safe only at boot. On those boards `E0` is also expected — the Air530Z driver supports GPS/GLONASS/BeiDou but not Galileo, and the firmware falls back automatically.
---
## Sensor Settings
| Command | Description |
|---------|-------------|
| `sensor list [<start_idx>]` | List custom sensor settings (paginated at 134 chars) |
| `sensor get <key>` | Get a custom sensor setting value by key |
| `sensor set <key> <value>` | Set a custom sensor setting value |
---
## Radio (Temporary Override)
| Command | Description |
|---------|-------------|
| `tempradio <freq>,<bw>,<sf>,<cr>,<timeout_mins>` | Apply temporary radio parameters; automatically reverts after `timeout_mins`. Constraints: freq 1502500 MHz, bw 7500 kHz, sf 512, cr 58. Saved prefs are never mutated — concurrent `set` commands and reboots both restore the real saved values. |
---
## Repeater Uplink (ESP32 + `CONFIG_ZEPHCORE_REPEATER_UPLINK`)
These commands configure observer-style WiFi+MQTT packet reporting from repeater role.
All `set uplink.*` changes are saved immediately and only applied after reboot.
| Command | Description |
|---------|-------------|
| `get uplink.status` | Uplink runtime state: enabled flag, WiFi state, MQTT state, reboot-required flag |
| `get uplink.enable` | Uplink enable flag (`on`/`off`) |
| `get uplink.wifi.ssid` | Configured WiFi SSID |
| `get uplink.mqtt.host` | Configured MQTT broker host |
| `get uplink.mqtt.port` | Configured MQTT broker port |
| `get uplink.mqtt.tls` | MQTT TLS mode (`0`/`1`) |
| `get uplink.mqtt.user` | Configured MQTT username |
| `get uplink.mqtt.iata` | Configured IATA/site code used in MQTT topic |
| `set uplink.enable <on\|off>` | Enable or disable repeater uplink *(reboot required)* |
| `set uplink.wifi.ssid <ssid>` | Set WiFi SSID *(reboot required)* |
| `set uplink.wifi.psk <psk>` | Set WiFi password *(reboot required)* |
| `set uplink.mqtt.host <host>` | Set MQTT host *(reboot required)* |
| `set uplink.mqtt.port <port>` | Set MQTT port 165535 *(reboot required)* |
| `set uplink.mqtt.tls <0\|1>` | Set MQTT TLS mode *(reboot required)* |
| `set uplink.mqtt.user <user>` | Set MQTT username *(reboot required)* |
| `set uplink.mqtt.password <pass>` | Set MQTT password *(reboot required)* |
| `set uplink.mqtt.iata <code>` | Set MQTT site code *(reboot required)* |
---
## `get` — Read Configuration
| Command | Returns |
|---------|---------|
| `get name` | Node name |
| `get role` | Firmware role: `repeater` or `room_server` (companion builds report `companion`) |
| `get repeat` | Forwarding enabled: `on` or `off` |
| `get radio` | Radio params as `freq,bw,sf,cr` — the same comma-separated form `set radio` takes, so a reply can be edited and sent straight back |
| `get freq` | Frequency in MHz |
| `get freqerr` | Carrier frequency error measured on received packets: `mean N Hz, min A, max B, K pkts`. **LR2021 only** — other radios answer `not available`. Purely diagnostic; nothing acts on it. **The mean only approximates *this* node's reference error once it is averaged over many different peers** — their individual errors cancel, ours does not — so read `K` and the min/max spread before believing it: a tight spread over a handful of packets is one chatty neighbour, not a population. Small values are the expected answer and mean there is nothing to do; LoRa tolerates carrier error up to roughly a quarter of the bandwidth before sensitivity suffers, so at BW 62.5 kHz a few hundred Hz is noise. If it is kHz-scale the correction is board-dependent: XTAL parts have `SetXoscCpTrim`, but **TCXO parts have no chip-side trim at all** (DS §6.11.4: "If a TCXO is configured, this command has no effect"), leaving only a software offset to the programmed frequency. Values beyond ±200 kHz are discarded by the driver and warn once — the field is decoded from three `GetLoraPacketStatus` bytes that DS rev 2.1 does not document, so implausible readings are evidence the field is not real on that firmware rather than a genuine measurement. Reset by `clear stats`. |
| `get tx` | TX power in dBm |
| `get lat` | Stored latitude |
| `get lon` | Stored longitude |
| `get dutycycle` | Duty cycle as percentage (e.g. "50.0%") |
| `get af` | Raw airtime factor value |
| `get txdelay` | Adaptive TX delay status: contention estimate and flood delay factor |
| `get rxdelay` | *(deprecated)* Always returns "adaptive (rxdelay deprecated)" |
| `get direct.txdelay` | *(deprecated)* Always returns "adaptive (direct.txdelay deprecated)" |
| `get backoff.multiplier` | Per-dupe reactive backoff multiplier |
| `get flood.max` | Max flood retransmit hops |
| `get flood.max.unscoped` | Max retransmit hops for un-scoped floods |
| `get flood.max.advert` | Max retransmit hops for ADVERT floods |
| `get flood.advert.interval` | Flood advertisement interval in hours |
| `get advert.interval` | Local advertisement interval in minutes |
| `get allow.read.only` | *(room server only)* Whether read-only clients are allowed |
| `get guest.password` | Guest access password |
| `get owner.info` | Owner/contact info (pipes `\|` display as newlines) |
| `get int.thresh` | Interference threshold |
| `get leds` | LED master switch: `on` or `off` |
| `get buzzer` | *(room server only)* Buzzer/vibration mode as `<n> (<name>)`: `0 (silent)`, `1 (sound+vib)`, `2 (vibrate)`, `3 (sound)`. Compiled out on repeater builds (`#ifndef ZEPHCORE_REPEATER`) — a repeater answers `unknown config: buzzer`. |
| `get agc.reset.interval` | Removed — replies `Removed - Automatic AGC reset is on`. Periodic AGC recalibration was deleted (it reset the noise floor to its unseeded sentinel on every fire). Use `set rxduty` to cut RX current. |
| `get multi.acks` | Extra ACK transmit count (`0` or `1`) |
| `get path.hash.mode` | Path hashing algorithm: `0`, `1`, or `2` |
| `get loop.detect` | Loop detection level: `off`, `minimal`, `moderate`, or `strict` |
| `get radio.rxgain` | RX gain boost: `on` or `off` |
| `get radio.fem.rxgain` | External FEM's LNA in the RX path: `on` (through the LNA) or `off` (bypassed). Default `on` |
| `get rxduty` | RX duty cycle mode: `0` or `1` |
| `get display.rotate` | Panel 180-degree rotation: `0` or `1`. Reports the **live panel state**, not the stored byte — the two differ only when a rotation was refused, which is the case worth seeing. Boards whose panel cannot rotate reply `unsupported (panel cannot rotate)` |
| `get input.rotate` | Joystick/D-pad axis swap: `0` or `1` |
| `get gps duty` | Now-effective GPS duty interval in seconds (`always on (0)` when continuous) |
| `get gps diag` | What the last GPS module-configuration attempt did — which path ran, bytes sent, and tracked satellites per constellation. See **GPS configuration diagnostics** in the GPS section for the field reference |
| `get meshtimesync` | Mesh time-sync state + live dry-run: on/off, eligible voter count, votes for/against, consensus skew and radius, would-be verdict (`ok`/`in-band`/`step±N`/`abstain (reason)`/`hold (reason)`; a recent clock set — manual or GPS — shows as `hold (suppressed)`, and a backward step a forward-only role would refuse is annotated `(skipped: forward-only)`), step counters, suppression countdown, and a per-sender evidence table (`prefix hops count skew E`, `E` = counted toward the verdict above). Entries that count print first, so a size-capped reply never hides the ones that explain the summary; if the table doesn't fully fit, a trailing `+N more` shows how many were left out. Sensing runs even while off, so this works as a dry-run before enabling. Over remote admin the reply is truncated to the packet size (summary always fits); the full table needs the USB CLI. |
| `get probe.interval` | Seconds between periodic radio measurements (noise-floor sample + CAD probe). 0 = CAD probing off |
| `get dc.restarts` | Duty-cycle re-arm counter — RxTimeout re-arms **plus** parked-RX watchdog recoveries, sharing one total. **Read it as a rate: divide by uptime.** A bare count is not interpretable, and the two sources it merges cost very differently. An RxTimeout re-arm is ~7 ms of deaf time (the `Calibrate(ALL)` gap in the driver's `restart_rx`) after which the chip returns to duty cycle immediately — packets, not power. A watchdog recovery means the chip sat parked in *full RX* for one to two watchdog periods (`2·(preamble+8)` symbols, floored at 250 ms) — power, not packets, since parked RX still receives. The counter cannot tell you which, so read the worst case. **Measured normal: ~250/hr on a high site at SF8/BW 62.5** (one every ~14 s), where the worst case — every event a park — costs about 3.5% of the duty cycle's savings. Nothing to act on below roughly **2000/hr**; above that the parked-RX share starts eating a meaningful fraction of the saving and it becomes worth splitting the counter to find out. A high rate means the preamble detector is tripping without a decodable packet following, which on an elevated site is usually distant marginal traffic rather than interference — cross-check `get cad.stats`, whose adaptive detPeak offset rises independently in a genuinely busy RF environment. Reset by `clear stats`. |
| `get cad` | Always `on` — ZephCore performs CAD/LBT unconditionally and has no enable knob. Kept as a boolean reply for Arduino MeshCore app compatibility; the real status lives in `get cad.stats`. |
| `get cad.stats` | Adaptive-CAD status: header (`a` auto on/off, `o` operating detPeak offset, `pk` absolute peak with family base, `sp` noise-floor RSSI burst quality as `mean-spread-dB/zero-spread-%` (plus `(burst-count rN/bN/aN)` on the local USB console, omitted over the air to protect the 161 B reply budget, where `r` is completed RSSI reads, `b` reads the chip refused as busy, and `a` bursts abandoned because of one — on a healthy radio `b`/`a` stay at 0, and a large `a` against a near-zero burst count is the signature of a sampler being refused rather than one losing the odd read) — a non-zero mean proves the 8 reads are independent however high the share climbs; only mean `0.0` with a high share indicts the sampler. See `ADAPTIVE_CAD.md`. `bc` busy cap), then a 3-rung window around the operating offset (`*` marks it) with probe/busy/fp/tp counts and false-positive rate — the three levels the knee controller reads. Probing runs even while `cad.auto` is off (dry-run), so this is the observation tool for picking a site-appropriate detPeak. See `ADAPTIVE_CAD.md`. Not available on SX127x boards (no hardware CAD). |
| `get extra.sf` | LR2021 side detectors: the extra spreading factors currently received alongside `sf`, comma-separated (bare, no `> ` prefix), or `No extra SF configured`. Reflects the saved prefs, not what the chip accepted — if the set became invalid after an `sf`/`bw` change it is reported here but was refused at boot (a `WRN` line says so). |
| `get adc.multiplier` | Battery voltage ADC calibration multiplier |
| `get bootloader.ver` | Bootloader version string |
| `get public.key` | Node's public key as hex. **Not** USB-only — it is answerable over remote admin, matching Arduino MeshCore. A public key is broadcast in every advert, so there is nothing to gate. |
| `get prv.key` | *(USB only)* Node's private key as hex — the 128-char expanded form, the same one `set prv.key` takes |
---
## `set` — Write Configuration
Changes are persisted immediately unless noted. Some require a reboot.
| Command | Constraints | Description |
|---------|-------------|-------------|
| `set name <name>` | No `[ ] \ : , ? *` | Set node name |
| `set repeat <on\|off>` | | Enable or disable packet forwarding |
| `set radio <freq>,<bw>,<sf>,<cr>` | freq 1502500, bw 7500, sf 512, cr 58 | **Comma-separated**, not space-separated — spaces parse as a single argument and the command is rejected. Set radio params *(reboot required)* |
| `set freq <mhz>` | 1502500 *(USB only)* | Set frequency alone *(reboot required)* |
| `set tx <dbm>` | 9 to board max (default 30) | Set TX power |
| `set lat <latitude>` | | Set stored latitude |
| `set lon <longitude>` | | Set stored longitude |
| `set dutycycle <pct>` | 1100 | Set duty cycle percentage (converted to airtime factor internally) |
| `set af <value>` | float | Set raw airtime factor directly |
| `set txdelay <value>` | | Accepted for prefs compatibility — **ignored** (txdelay is adaptive) |
| `set rxdelay <value>` | | Accepted for prefs compatibility — **ignored** (rxdelay is adaptive) |
| `set direct.txdelay <value>` | | Accepted for prefs compatibility — **ignored** (direct.txdelay is adaptive) |
| `set backoff.multiplier <m>` | 0.02.0 | Per-dupe reactive backoff multiplier (0 = disable reactive backoff) |
| `set flood.max <count>` | 064 | Maximum flood retransmit hops |
| `set flood.max.unscoped <count>` | 064 | Hop limit for un-scoped floods only (default 64 = same as flood.max); scoped/transport floods still use flood.max |
| `set flood.max.advert <count>` | 064 | Hop limit for ADVERT floods only (default 8); curbs advert churn independent of flood.max |
| `set flood.advert.interval <hours>` | `0` (off) or 3168 | How often the repeater floods its own advertisement. `0` disables periodic flood adverts. |
| `set advert.interval <mins>` | `0` (off) or min240 | How often the repeater sends local (zero-hop) advertisements. `0` — the default — disables them. Stored halved (the pref holds minutes/2), so odd values round down. |
| `set allow.read.only <on\|off>` | | *(room server only)* Allow or deny read-only client connections |
| `set guest.password <pwd>` | | Set guest access password |
| `set owner.info <text>` | Use `\|` for newlines | Owner/contact information |
| `set int.thresh <value>` | | Interference detection threshold |
| `set buzzer <0\|1\|2\|3>` | or `off` / `on` / `vibrate` / `sound` | *(room server only)* `0`/`off` silent, `1`/`on` sound + vibration, `2`/`vibrate` vibration only, `3`/`sound` sound only. Modes 2 and 3 need a vibration motor; without one the node replies `Error: no vibration motor on this board - use 0 or 1`. Applied live and persisted. Compiled out on repeater builds. |
| `set leds <on\|off\|1\|0>` | default **on** | Master switch for every LED on the node, applied live and persisted: heartbeat, unread-message and LoRa TX-activity LEDs, plus the message and shutdown flashes. Works on every role, including headless repeaters where the TX LED is the only one that ever lights. Does **not** cover the display backlight, which is a separate UI brightness setting. |
| `set agc.reset.interval <ms>` | Accepted, ignored | Removed — replies `Removed - Automatic AGC reset is on`. The prefs byte is still read and written so the on-flash layout stays byte-exact, but nothing acts on it. |
| `set multi.acks <0\|1>` | | Enable extra ACK transmits |
| `set path.hash.mode <mode>` | 0, 1, or 2 | Path hashing algorithm |
| `set loop.detect <mode>` | `off`, `minimal`, `moderate`, `strict` | Loop detection sensitivity |
| `set radio.rxgain <0\|1\|on\|off>` | | RX gain boost, applied live. Replies `Error: unsupported` on radios without RX boost (SX127x); the pref is still saved. |
| `set radio.fem.rxgain <0\|1\|on\|off>` | default **1** | Routes receive through the external FEM's LNA (`1`) or around it via the FEM's bypass path (`0`), applied live. Sensitivity for battery life — `0` costs roughly 17 dB and saves the LNA's supply current. Transmit, and the driver's idle/sleep gating of the FEM, are unaffected either way. Supported only where the FEM's receive path is software-selectable and that select line is wired to the radio node as `lna-bypass-gpios` — today the three KCT8103L boards, `heltec_t096`, `heltec_wireless_tracker_v2` and `heltec_wifi_lora32_v43`. Every other board reports `Error: unsupported`: `heltec_wifi_lora32_v4`'s GC1109 has no receive-path select (its CPS is don't-care in RX, same as MeshCore); `station_g2`, `gat562_30s`, `ikoka_nano_30dbm` and `promicro_sx1262` have only the DIO2/TXEN/RXEN transmit-receive switch; `rak3401_1watt`'s SKY66122 is enabled by a standalone always-on regulator outside the radio node; and non-SX126x radios (LR1110, LR2021, SX127x) never implement it. The pref is still saved when unsupported. **Do not expect the FEM's chip-enable to be the knob** — deasserting `antenna-enable-gpios` in RX shuts the part down and takes the through path with it (~69 dB measured on a V4.3), which is what 1.17.2 did before this moved to `lna-bypass-gpios`. |
| `set rxduty <0\|1\|on\|off>` | | RX duty cycle mode *(reboot required)*. Window timing auto-sized per SF/BW/preamble from the SX126x datasheet constraints (boot log line `rxduty:` shows the result). Zero-loss guarantee assumes senders on preamble-32 firmware (current MeshCore at SF≤8); legacy preamble-16 senders are only caught ~50% worst-phase — keep off until the local mesh has converted. Presets with 16-symbol preambles (SF≥9) fall back to continuous RX automatically. |
| `set display.rotate <0\|1\|on\|off>` | default **0** | Rotate the display 180 degrees, for cases and upgrade kits that mount the screen upside down (e.g. the Meshnology N37E for the Wio Tracker L1). Applied live — the driver flips the panel's `SEGMENT_MAP` and `COM_OUTPUT_SCAN`, two bytes on the wire, and the next frame comes out rotated with no redraw and no per-frame cost. **Only full-height SSD1306 and SH1106 panels support this** (`rak4631`, `gat562_30s`, `heltec_wifi_lora32_v4`/`v43`, `lilygo_t3s3`, `station_g2`, `wio_tracker_l1`); every other panel replies `Error: this panel cannot rotate` and the pref is **not** saved, so a stored value can never disagree with what the screen shows. `lilygo_timpulse_plus` is excluded despite being an SSD1306: its 64x32 glass is windowed into a 128x64 controller at `page-offset 4`, and the COM-scan reversal flips the controller's whole range, which would move the image off the bonded region. E-paper (SSD16xx) is excluded on purpose: its driver accepts a 180-degree orientation but implements it by flipping the RAM entry mode only, which reverses byte order without reversing bit order inside each byte — it would report success and render wrong. |
| `set input.rotate <0\|1\|on\|off>` | default **0** | Swap the joystick/D-pad axes — up/down and left/right — to match an upside-down mount. Applied live. Deliberately **separate** from `display.rotate`: a case can flip the screen without moving the stick, and boards whose panel cannot rotate can still need the axis swap. Works on every board with directional input, in both the joystick UI and the button UI (where it swaps page-prev/page-next). Non-directional keys, tap codes and long-press gestures are unaffected. |
| `set adc.multiplier <mult>` | `0` (use board default) or 10030000 | Battery voltage ADC calibration multiplier, set directly. Rejects non-numeric input, NaN/inf and negatives. |
| `set adc.multiplier target <mv>` | 30004400 mV | Calibrate against a voltage you measured with a multimeter: rescales the current multiplier so the ADC reads `<mv>`. Replies with the old and new multiplier plus the before/after reading. `Error: no ADC reading on this board` if the board has no battery ADC. |
| `set adc.multiplier full` | board must be fully charged | Same calibration, but against the board's battery-curve 100% point instead of a hand-measured value. Only meaningful on a full charge. |
| `set meshtimesync <on\|off>` | default **off** | Mesh time sync: automatically correct this node's clock from the consensus of Ed25519-signed advert timestamps heard on the mesh. Steps at most ±1 h per step, one step per 6 h; abstains without a quorum (default 6) of tenured agreeing senders; never overrides a clock set in the last 7 days, whether from GPS (re-armed on every fix) or a manual set. See `MESHTIMESYNC.md`. |
| `set cad.auto <on\|off>` | default **on** | Adaptive CAD: let the staircase controller move the operating detPeak offset based on probe statistics. On by default (repeaters and companions); at the default 15 s probe interval it responds to environment change in ~12 h. Turn off to observe/hand-tune via `get cad.stats` + `set cad.offset`. See `ADAPTIVE_CAD.md`. |
| `set cad.offset <n>` | 8 to 12, default 0 | Operating detPeak offset from the chip family's base for the current SF, bandwidth and CAD symbol count (Semtech LoRa Basics Modem reference tables; SX126x ~1834, LR11xx ~5085, LR20xx its own symbol-indexed table). Negative = more sensitive LBT (catches weaker signals, risks false busy), positive = less sensitive. Wide range so dense hilltops / quiet valleys can settle far from base. The per-family absolute clamp in the driver (SX126x 1248, LR11xx 40100, LR20xx 4890) is a firmware guardrail against a CAD that never/always fires, not a chip limit (`cadDetPeak` is a full `uint8_t`); the driver reports it so the controller narrows this range to match rather than exploring offsets that collapse onto one peak. Applied live; the auto staircase may move it later if `cad.auto` is on. |
| `set probe.interval <sec>` | 0 (off) or 10255, default **15** | Seconds between periodic radio measurements. ONE reading serves both: the noise-floor RSSI sample (median of 8) and the CAD calibration probe, which consumes that same reading rather than measuring separately — so this is also the noise-floor sampling rate, and it sets how often an idle repeater wakes. Default 15 s → ~12 h CAD staircase response; the floor EMA warms up over 8 samples (~2 min) and its unguarded bypass runs every 16th (~4 min). Longer = fewer wakes, slower to track a changing RF environment. 0 disables CAD probing entirely (also freezes auto adaptation); the floor sampler then falls back to its build-time default. |
| `set cad.busycap <pct>` | 0 (off) or 1090, default **25** | Airtime-protection cap: the max percentage of TX attempts the node will let CAD defer before the staircase backs off to a less sensitive detPeak — counting **real** traffic, not just false positives. On a congested hilltop most busy verdicts are distant traffic won on capture anyway, so deferring for all of it starves the node's own airtime. Self-targeting: a quiet node's busy rate never reaches the cap. Shown as `bc:` in `get cad.stats`. 0 disables the cap (pure knee-seeking). |
| `set cad.reset` | | Clear the accumulated per-level CAD probe statistics (RAM only; also cleared automatically on any radio parameter change). |
| `set extra.sf <sf> [sf] [sf]` | up to 3 SFs, `0`/`off` clears | **LR2021 only** (`Error: unsupported` elsewhere) — LoRa *side detectors*: demodulate up to three extra spreading factors concurrently with `sf`, on the same bandwidth, so one repeater can serve several SF communities. Which SF a packet arrived on is a chip-side readout, not a guess. Chip constraints, enforced in the driver and reported as `Error: unsupported or invalid extra SF config`: every extra SF must be **greater** than `sf`, all distinct, highestlowest ≤ 4, and at BW ≥ 500 kHz at most 2 (only 1 when `sf` ≥ 10). **Receive only, and the bridge it creates is one-way.** TX always uses the single configured `sf`, and all detectors share one bandwidth, so this is multi-SF, not multi-channel. A node with `sf 7` + `extra.sf 8` hears SF8 traffic and *does* forward it — but the forward goes out at SF7, so traffic moves SF8 -> SF7 only and nothing comes back. An SF8 node's direct messages are delivered while its ACKs never arrive, so it retries to its limit every time; adverts and one-way flood traffic propagate fine. Because every extra SF must be **greater** than `sf`, the main SF is always the lowest in the set and TX always uses it — so the bridge direction is fixed at high-SF-in / low-SF-out and **cannot be reversed**. Two nodes back to back both point the same way; there is no configuration that carries SF7 -> SF8. Treat it as a collector for slower-SF stragglers, not as a link between two SF islands. Applied live and restored on every RX entry. **Interaction with CAD:** the chip's SF constraint for CAD is the inverse of the one for RX, so the driver switches side detectors off for each LBT CAD and back on when RX re-arms — two extra SPI commands per TX, no configuration required. Persisted; a set that no longer fits after an `sf`/`bw` change is refused at boot and logged. |
| `set prv.key <hex>` | **128-char hex** (64-byte expanded Ed25519 key) | Replace private key; derive new identity *(reboot to apply)*. The length must be exact — `fromHex` rejects anything else with `Error, bad key`. `get prv.key` returns the same 128-char form. Not USB-gated. |
---
## Notes
- **USB-only commands**`get acl`, `get prv.key`, `set freq`, `log` (dump), `stats-packets`, `stats-radio`, `stats-core`, `erase` — are blocked when the command arrives over the mesh (remote admin). These are the only ones gated on `sender_timestamp == 0`; `get public.key` and `set prv.key` are **not** among them.
- **Adaptive contention window**`txdelay`, `rxdelay`, and `direct.txdelay` are accepted and stored for Arduino prefs compatibility but have no effect. Use `get txdelay` to inspect the current adaptive state and `set backoff.multiplier` to tune reactive backoff.
- **Region load mode** — after `region load`, every line received is parsed as a region entry until a blank line is sent. The loaded map is only committed to the live region tree at that point; use `region save` to persist it. Region rows must be indented by at least one space, so an **unindented line that starts with a name character aborts the mode and is executed as a normal command** — the escape hatch if a `region load` is started by accident or a client dies mid-transfer. An abort discards the partial map, leaving the live region tree untouched. The exported wildcard header line `*` stays unindented and is ignored as before, so pasting the output of `region` still loads cleanly.
- **Reboot delay**`start dfu`, `start ota` (nRF52 BLE-DFU path only), `reboot`, `clkreboot` and `erase` defer the reset by **2 seconds** so the reply can be transmitted over LoRa first. On a companion the handler then keeps deferring in 20 ms steps until the BLE/USB transport has drained, up to a further 3 s grace. On ESP32 `start ota` starts a WiFi AP + HTTP server and does **not** reboot.
+124 -107
View File
@@ -1,107 +1,124 @@
# ZephCore 1.17.4-zephcore
Storage housekeeping. The repeater's `erase` command never actually erased anything, a node flashed
from another firmware could start out with somebody else's leftovers underneath it, and switching a
node between companion and repeater firmware quietly let the two share the same 128 KB. All three are
fixed, and the last one is now deliberate and loud rather than quiet.
> [!IMPORTANT]
> **Read the role-switching section before you flash a different role onto an existing node.** A
> companion that gets repeater firmware — or the reverse — now erases itself on first boot. That is
> intentional, but it is new. Export your identity first if you want to keep it.
> [!NOTE]
> A normal upgrade is unaffected. Repeater to repeater, or companion to companion, keeps your
> identity, settings, contacts and phone pairing exactly as before.
---
## `erase` now erases
On a repeater or room server, `erase` promised to format the entire filesystem. It did not. It deleted
the handful of files it had put in its own folder and cleared the phone pairings, and left everything
else exactly where it was.
Most of the time nobody noticed, because on a healthy node those files *are* everything that matters.
It mattered when the node was not healthy — which is precisely when somebody reaches for `erase`. If
anything had written into the storage area from outside, deleting our own files could not undo it, and
the command reported success while the problem stayed.
`erase` now wipes the storage area itself, the phone-pairing store, and external flash where a board has
it, then reboots. The node comes back with a new identity and default settings, exactly like a node out
of the box.
> [!IMPORTANT]
> **This is a genuine factory reset now, and it takes the identity with it.** Anyone who had your node
> in their contacts will need to add it again, and an admin password, ACL and region map all go too.
> That was always what the command claimed to do; it is now what it does.
The companion's `erase` already worked this way. Repeater, room server and observer share one
implementation with it now, so there is one behaviour to remember instead of two.
---
## Switching a node between roles now wipes it
Companion firmware and repeater firmware kept their files in separate folders, and until now each left
the other's alone. Flashing back and forth preserved both sets.
That sounds generous and was not. The two roles share a single 128 KB storage area. A companion that has
collected a few hundred contacts and a full advert cache leaves noticeably less room for a repeater's
region map and access list, and a write that no longer fits simply fails. The node is not corrupted —
the two roles' files never sit on top of each other — it just runs out of space for reasons its owner
cannot see, because half of what is stored belongs to firmware that is not running.
They are also two quite different kinds of node, and treating one machine as quietly holding both was
never worth the space it cost.
From 1.17.4, each role checks on first boot whether the storage belongs to it, and formats everything if
not. So a repeater flashed onto a former companion starts empty, and a companion flashed onto a former
repeater starts empty.
> [!IMPORTANT]
> **Export your identity before switching roles.** The node's identity, settings, contacts, channels,
> access list, region map and phone pairings all go. There is no undo and no warning prompt — the first
> boot on the new firmware has already done it by the time you see anything.
> [!NOTE]
> **Repeater, room server and observer still share.** Those three keep their files in the same place and
> use the same settings layout, so moving between them keeps the node's identity and configuration. It
> is the companion that is now separate.
---
## A node coming from other firmware starts clean
Flashing ZephCore onto hardware that was running something else is a normal thing to do, and it used to
leave more behind than anyone expected.
Nothing about installing firmware erases storage. Dragging a UF2 file writes the program and nothing
else, and each firmware only ever clears the piece of flash it believes is its own. On the nRF52840
boards, Arduino MeshCore's storage sits inside the same region ZephCore uses, so the two overlap — and
whichever one boots first tidies up its own corner and leaves the rest of the other's files sitting
there. The result on one Seeed Solar Node was a repeater that came up looking perfectly healthy and
silently refused to forward anything, because a single setting deep inside its configuration had been
overwritten by bytes that belonged to a different firmware.
Each role now checks on first boot whether the storage is its own and, if not, clears the whole lot —
the storage area, the phone-pairing store, and external flash — before writing anything. A node arriving
from another firmware, or from a factory-fresh chip, starts from a known state instead of an inherited
one.
> [!IMPORTANT]
> **Moving between Arduino MeshCore and ZephCore still needs an erase in both directions.** ZephCore now
> cleans up on the way in, but it cannot clean up on the way out — going back to Arduino MeshCore leaves
> ZephCore's files inside the area Arduino will use. Run the formatter UF2, or a full chip erase, when
> you switch either way. This is not new advice; it is now written down.
---
## Also in this release
Nothing here changes how a node behaves.
- **A wasted erase on the companion.** Running `erase` from the companion's USB console formatted the
storage, then formatted it a second time on the reboot that followed, because the marker saying "this
node has been set up" went out with everything else. The pairing-based factory reset never had this
problem. Both paths behave the same way now.
# ZephCore 1.17.4-zephcore
Storage housekeeping, plus a listen-before-talk fix. The repeater's `erase` never actually erased,
a node flashed from another firmware could start out with somebody else's leftovers underneath it,
and switching a node between companion and repeater firmware quietly let the two share the same
128 KB. Separately, the channel-activity detector was using the wrong reference table on LR1110
boards.
> [!IMPORTANT]
> **Read the role-switching section before you flash a different role onto an existing node.** A
> companion that gets repeater firmware — or the reverse — now erases itself on first boot. That is
> intentional, but it is new. Export your identity first if you want to keep it.
> [!NOTE]
> A normal upgrade is unaffected. Repeater to repeater, or companion to companion, keeps your
> identity, settings, contacts and phone pairing exactly as before.
---
## `erase` now erases
On a repeater or room server, `erase` promised to format the entire filesystem. It deleted the files
in its own folder and cleared the phone pairings, and left everything else where it was.
That only mattered when a node was unhealthy — which is precisely when somebody reaches for `erase`.
If anything had written into the storage area from outside, deleting our own files could not undo it,
and the command reported success while the problem stayed.
`erase` now wipes the storage area, the phone-pairing store, and external flash where a board has it,
then reboots. The node comes back exactly like one out of the box.
> [!IMPORTANT]
> **This is a genuine factory reset now, and it takes the identity with it.** Anyone who had your node
> in their contacts will need to add it again, and the admin password, ACL and region map go too.
The companion's `erase` already worked this way. Repeater, room server and observer now share its
implementation, so there is one behaviour to remember instead of two.
---
## Switching a node between roles now wipes it
Companion and repeater firmware keep their files in separate folders, and until now each left the
other's alone. Flashing back and forth preserved both sets.
That sounds generous and was not. The two roles share a single 128 KB storage area, so a companion's
few hundred contacts and full advert cache leave noticeably less room for a repeater's region map and
access list — and a write that no longer fits simply fails. Nothing is corrupted; the node just runs
out of space for reasons its owner cannot see, because half of what is stored belongs to firmware that
is not running.
From 1.17.4 each role checks on first boot whether the storage belongs to it, and formats everything
if not.
> [!IMPORTANT]
> **Export your identity before switching roles.** Identity, settings, contacts, channels, access list,
> region map and phone pairings all go. There is no undo and no prompt — the first boot on the new
> firmware has already done it by the time you see anything.
> [!NOTE]
> **Repeater, room server and observer still share.** Those three keep their files in the same place
> and use the same settings layout, so moving between them keeps identity and configuration. It is the
> companion that is now separate.
---
## A node coming from other firmware starts clean
Nothing about installing firmware erases storage. Dragging a UF2 writes the program and nothing else,
and each firmware only clears the piece of flash it believes is its own. On the nRF52840 boards,
Arduino MeshCore's storage sits inside the region ZephCore uses, so whichever boots first tidies its
own corner and leaves the rest. On one Seeed Solar Node that produced a repeater which came up looking
perfectly healthy and silently refused to forward anything, because a single setting deep inside its
configuration had been overwritten by another firmware's bytes.
Each role now checks on first boot whether the storage is its own and, if not, clears the whole lot
before writing anything.
> [!IMPORTANT]
> **Moving between Arduino MeshCore and ZephCore still needs an erase in both directions.** ZephCore
> cleans up on the way in but cannot clean up on the way out. Run the formatter UF2, or a full chip
> erase, when you switch either way.
---
## Listen-before-talk was too cautious on LR1110 boards
Before transmitting, a node listens for a LoRa signal already on the air. How faint a signal counts is
set by a per-chip threshold, and ZephCore tunes it automatically from what each node measures.
The starting values for that tuning came from a reference table — and on the LR1110 it was the wrong
table, copied from a different Semtech chip and read at the wrong setting. It started roughly five
steps too insensitive, so those nodes spent weeks walking the threshold down and still hit the limit of
how far they were allowed to adjust. Two nodes sitting in one room made it visible: an SX1262 settled
one step from its starting point while the LR1110s next to it were pinned at the end of their range.
The tables now come from Semtech's own reference code, and they take **bandwidth** into account, which
nothing did before. That barely moves the SX1262 — a count or two, and nothing at all at the default
preset — but on the LR1110 bandwidth is worth around twelve counts per doubling, which is most of the
error. The range each node may adjust within is wider, and the radio now tells the tuner where its own
limits are, so a node can no longer sit against a wall it cannot see.
Affected boards: **T1000-E**, **ThinkNode M3** and **ThinkNode M9**. On SX1262 boards nothing changes
unless you run a 250 or 500 kHz bandwidth, where the old value was up to ten counts too sensitive.
> [!NOTE]
> **Run `set cad.reset` after upgrading.** The tuning statistics your node collected are measured
> against the old starting point and are not comparable to the new one. Clearing them lets the tuner
> re-converge cleanly; left alone it blends two sets of readings. Everything else is automatic.
> [!IMPORTANT]
> This is a first release of the corrected tables. They are verified against Semtech's reference and
> against on-air measurements from three nodes, but not yet across a season or a busy site. If a node
> starts deferring noticeably more or less than it used to, `get cad.stats` shows what it is measuring.
---
## Also in this release
Nothing here changes how a node behaves.
- **A wasted erase on the companion.** Running `erase` from the companion's USB console formatted the
storage, then formatted it again on the reboot that followed, because the marker saying "this node
has been set up" went out with everything else. Both paths behave the same way now.
+16
View File
@@ -123,4 +123,20 @@ uint8_t LR1110Radio::hwCadBasePeak()
return lr11xx_cad_base_peak(_dev);
}
/* The detPeak range lr11xx_do_cad() will actually program. Must match the
* driver's clamp exactly: if the adapter thinks the range is wider, the
* staircase explores offsets that collapse onto one peak and reads the noise
* between them as curvature. Same reasoning as LR2021Radio::hwCadPeakMin
* and the same symptom was observed here on T1000-E companions, which sat at
* o:-8 with the driver's old floor of 48 already reached. */
uint8_t LR1110Radio::hwCadPeakMin()
{
return lr11xx_cad_peak_min();
}
uint8_t LR1110Radio::hwCadPeakMax()
{
return lr11xx_cad_peak_max();
}
} /* namespace mesh */
+2
View File
@@ -40,6 +40,8 @@ protected:
int hwCadProbe(int8_t level) override;
void hwCadSetPeakOffset(int8_t offset) override;
uint8_t hwCadBasePeak() override;
uint8_t hwCadPeakMin() override;
uint8_t hwCadPeakMax() override;
};
} /* namespace mesh */
+14
View File
@@ -151,6 +151,20 @@ uint8_t SX126xRadio::hwCadBasePeak()
return sx126x_cad_base_peak(_dev);
}
/* The detPeak range sx126x_do_cad() will actually program. Must match the
* driver's clamp exactly: if the adapter thinks the range is wider, the
* staircase explores offsets that collapse onto one peak and reads the noise
* between them as curvature. Same reasoning as LR2021Radio::hwCadPeakMin. */
uint8_t SX126xRadio::hwCadPeakMin()
{
return sx126x_cad_peak_min();
}
uint8_t SX126xRadio::hwCadPeakMax()
{
return sx126x_cad_peak_max();
}
uint32_t SX126xRadio::getDutyCycleTimeoutRestarts() const
{
return sx126x_get_dc_timeout_restarts(_dev);
+2
View File
@@ -43,6 +43,8 @@ protected:
int hwCadProbe(int8_t level) override;
void hwCadSetPeakOffset(int8_t offset) override;
uint8_t hwCadBasePeak() override;
uint8_t hwCadPeakMin() override;
uint8_t hwCadPeakMax() override;
};
} /* namespace mesh */
@@ -1698,20 +1698,97 @@ int16_t lr11xx_get_chip_temp_c(const struct device *dev)
/* ── Driver API: CAD ────────────────────────────────────────────────── */
/* Recommended cad_detect_peak values per SF for 2-symbol CAD.
* From Semtech SX1261/62/68 / LR1110 reference (same silicon IP). */
static uint8_t lr11xx_cad_detect_peak(uint8_t sf)
/* Recommended cad_detect_peak, from Semtech's own reference stack:
* LoRa Basics Modem v4.9.0, ral_lr11xx.c ral_lr11xx_get_lora_cad_det_peak().
*
* Provenance matters here, because the table this replaces was wrong twice
* over. It was `{56,56,56,58,58,60,64,68}`, labelled "from SX1261/62/68 /
* LR1110 reference (same silicon IP)" — but that is byte-for-byte the *LR20xx*
* 2-symbol row (ral_lr20xx.c), i.e. the wrong chip family, sampled at the wrong
* symbol count. The SX126x scale is ~20-35 and shares nothing with this one.
* The error was worst at SF6/SF7, where it read 56 against Semtech's 52, and it
* is what drove field units eight rungs down to the offset rail: measured on
* two T1000-E companions at SF7/BW62.5, both pinned at o:-8 with a flat, clean
* FP curve, one of them also sitting on the driver's own peak clamp.
*
* Unlike the LR20xx, this family's detPeak is strongly bandwidth-dependent
* at SF7 Semtech spans 52/64/77 across BW125/250/500, ~12 counts per octave,
* against ~1-3 per octave on the SX126x. A bandwidth-blind base table is
* therefore a much larger error here than it is there, which is precisely why
* the SX1262 in the same room settled at offset -1 while these walked to -8.
*
* Below BW125 Semtech returns RAL_STATUS_UNKNOWN_VALUE and offers nothing. We
* run BW62.5 by default, so that gap is our normal operating point. We reuse
* the BW125 row there rather than extrapolating the trend downward: the curve
* is empirical PER-test data with visible noise (SF9 breaks monotonicity in all
* three brackets), a one-octave extrapolation at SF7 would invent ~40, and we
* already run a closed-loop controller whose entire job is to find the local
* value. Reusing BW125 leaves the adaptive offset a short, well-centred walk
* instead of substituting a guess for a measurement we take anyway. */
static uint8_t lr11xx_cad_detect_peak(uint8_t sf, uint16_t bw_khz, uint8_t symb_nb)
{
switch (sf) {
case 5: case 6: return 56;
case 7: return 56;
case 8: return 58;
case 9: return 58;
case 10: return 60;
case 11: return 64;
case 12: return 68;
default: return 60;
/* SF5 SF6 SF7 SF8 SF9 SF10 SF11 SF12 */
static const uint8_t bw500[8] = { 65, 70, 77, 85, 78, 80, 79, 82 };
static const uint8_t bw250[8] = { 60, 61, 64, 72, 63, 71, 73, 75 };
static const uint8_t bw125[8] = { 56, 52, 52, 58, 58, 62, 66, 68 };
const uint8_t *row;
int peak;
if (sf < 5 || sf > 12) {
sf = 9; /* mid-range fallback */
}
if (bw_khz >= 500) {
row = bw500;
} else if (bw_khz >= 250) {
row = bw250;
} else {
/* BW125 and everything narrower — see the note above. */
row = bw125;
}
peak = (int)row[sf - 5];
/* More symbols means more looks at the same correlation, so the same
* detection quality is reached at a lower threshold. Semtech applies
* this correction after the table lookup; we run 4 symbols everywhere
* (LORA_CAD_SYMB_4 in LoRaRadioBase::buildModemConfig), so it always
* bites, and omitting it was one further count of the SF7 error. */
if (symb_nb >= 8) {
peak -= 2;
} else if (symb_nb >= 4) {
peak -= 1;
}
return (uint8_t)peak;
}
/* The detPeak range this driver will actually program. Exported through
* lr11xx_cad_peak_min/max() so the C++ adaptive-CAD controller can narrow its
* offset window to match: where base+offset falls outside this, several offsets
* collapse onto one peak and the staircase reads sampling noise between
* identical configurations as curvature. That is not hypothetical it is the
* documented failure mode on the LR2021 (see LR2021Radio::hwCadPeakMin), and
* the old 48 floor here reproduced it on the LR1110 at SF7.
*
* The bounds are chosen so the clamp never truncates the offset window itself:
* the lowest base this table yields is 51 (SF6/SF7, BW<=125, 4 symbols), and
* CAD_LEVEL_MIN is -8, so anything above 43 would silently collapse the bottom
* rungs; the highest base is 85 (SF8, BW500) and CAD_LEVEL_MAX is +12. Within
* those, CAD_LEVEL_MIN/MAX remain the real limit and this is only a guardrail
* against "CAD never fires" / "CAD always busy". 40 is also roughly where
* Semtech's own BW trend extrapolates for the sub-125 bandwidths it declines to
* tabulate, which is where our default preset lives. */
#define LR11XX_CAD_PEAK_MIN 40
#define LR11XX_CAD_PEAK_MAX 100
uint8_t lr11xx_cad_peak_min(void)
{
return LR11XX_CAD_PEAK_MIN;
}
uint8_t lr11xx_cad_peak_max(void)
{
return LR11XX_CAD_PEAK_MAX;
}
static int lr11xx_do_cad(struct lr11xx_data *data)
@@ -1720,23 +1797,23 @@ static int lr11xx_do_cad(struct lr11xx_data *data)
struct lora_modem_config *mc = &data->modem_cfg;
uint8_t sf = (uint8_t)mc->datarate;
uint8_t symb_nb = 2;
uint8_t detect_peak = lr11xx_cad_detect_peak(sf);
/* Both the table lookup and the timeout need the symbol count, so it is
* resolved before the base peak rather than after it. */
uint8_t symb_nb = mc->cad.symbol_num ? (uint8_t)mc->cad.symbol_num : 2;
uint16_t bw_khz = (uint16_t)bw_enum_to_khz(mc->bandwidth);
uint8_t detect_peak = lr11xx_cad_detect_peak(sf, bw_khz, symb_nb);
if (mc->cad.symbol_num != 0) {
symb_nb = (uint8_t)mc->cad.symbol_num;
}
if (mc->cad.detection_peak != 0) {
detect_peak = mc->cad.detection_peak;
} else if (data->cad_peak_offset != 0) {
/* Adaptive-CAD operating offset (base +/- learned delta).
* LR11xx detPeak scale is ~48-90 never mix with SX126x. */
* LR11xx detPeak scale is ~50-85 never mix with SX126x. */
int peak = (int)detect_peak + data->cad_peak_offset;
if (peak < 48) {
peak = 48;
} else if (peak > 90) {
peak = 90;
if (peak < LR11XX_CAD_PEAK_MIN) {
peak = LR11XX_CAD_PEAK_MIN;
} else if (peak > LR11XX_CAD_PEAK_MAX) {
peak = LR11XX_CAD_PEAK_MAX;
}
detect_peak = (uint8_t)peak;
}
@@ -1845,7 +1922,15 @@ uint8_t lr11xx_cad_base_peak(const struct device *dev)
{
struct lr11xx_data *data = dev->data;
return lr11xx_cad_detect_peak((uint8_t)data->modem_cfg.datarate);
/* Must mirror lr11xx_do_cad()'s lookup exactly — bandwidth and symbol
* count included. This is what `get cad` prints as the base and what
* the C++ staircase offsets from, so a base that disagreed with the
* peak actually programmed would make every rung a lie. */
return lr11xx_cad_detect_peak(
(uint8_t)data->modem_cfg.datarate,
(uint16_t)bw_enum_to_khz(data->modem_cfg.bandwidth),
data->modem_cfg.cad.symbol_num
? (uint8_t)data->modem_cfg.cad.symbol_num : 2);
}
int lr11xx_cad_probe(const struct device *dev, int8_t peak_offset)
@@ -1855,10 +1940,10 @@ int lr11xx_cad_probe(const struct device *dev, int8_t peak_offset)
int peak = base + peak_offset;
int ret;
if (peak < 48) {
peak = 48;
} else if (peak > 90) {
peak = 90;
if (peak < LR11XX_CAD_PEAK_MIN) {
peak = LR11XX_CAD_PEAK_MIN;
} else if (peak > LR11XX_CAD_PEAK_MAX) {
peak = LR11XX_CAD_PEAK_MAX;
}
/* One-shot absolute override consumed by lr11xx_do_cad(). Probes and
@@ -132,10 +132,28 @@ void lr11xx_cad_set_peak_offset(const struct device *dev, int8_t offset);
* @brief Per-SF base cadDetPeak for the currently configured SF
*
* @param dev LoRa device
* @return Base detPeak (56-68 on this family)
* @return Base detPeak for the current SF, bandwidth and CAD symbol count
* (roughly 50-85 on this family; strongly bandwidth-dependent)
*/
uint8_t lr11xx_cad_base_peak(const struct device *dev);
/**
* @brief Lowest detPeak this driver will program.
*
* The C++ adaptive-CAD controller narrows its offset window to this range so it
* never explores offsets that collapse onto one peak.
*
* @return Minimum absolute detPeak
*/
uint8_t lr11xx_cad_peak_min(void);
/**
* @brief Highest detPeak this driver will program.
*
* @return Maximum absolute detPeak
*/
uint8_t lr11xx_cad_peak_max(void);
/**
* @brief Run one blocking calibration CAD at base detPeak + peak_offset
*
@@ -162,13 +162,30 @@ void sx126x_reset_dc_timeout_restarts(const struct device *dev);
void sx126x_cad_set_peak_offset(const struct device *dev, int8_t offset);
/**
* @brief Per-SF base cadDetPeak for the currently configured SF
* @brief Base cadDetPeak for the current SF, bandwidth and CAD symbol count
*
* @param dev LoRa device
* @return Base detPeak (SF + 13 on this family)
* @return Base detPeak (roughly 18-34 on this family)
*/
uint8_t sx126x_cad_base_peak(const struct device *dev);
/**
* @brief Lowest detPeak this driver will program.
*
* The C++ adaptive-CAD controller narrows its offset window to this range so it
* never explores offsets that collapse onto one peak.
*
* @return Minimum absolute detPeak
*/
uint8_t sx126x_cad_peak_min(void);
/**
* @brief Highest detPeak this driver will program.
*
* @return Maximum absolute detPeak
*/
uint8_t sx126x_cad_peak_max(void);
/**
* @brief Run one blocking calibration CAD at base detPeak + peak_offset
*
@@ -461,6 +461,56 @@ TX. It is a bare GPIO with no SPI and no chip state behind it, and a node
parked in continuous RX may not make an RX/TX/sleep transition for minutes --
long enough for the CLI to acknowledge a change the radio had not made.
== Bandwidth-aware CAD detPeak base table ==
cadDetPeak was SF+13 for every configuration. That is RadioLib's default and
it is a reasonable number, but it ignores bandwidth, and the datasheet does not
justify it: rev 2.2 Sec 13.4.7 gives no table at all, saying only that the
values "must be carefully tested", and defers to AN1200.48 (paywalled).
Semtech's own reference stack does have one. LoRa Basics Modem v4.9.0,
ral_sx126x.c ral_sx126x_get_lora_cad_det_peak(), brackets on bandwidth:
BW >= 500 kHz 22 23 25 26 30 31 33 35 (SF5..SF12)
BW >= 125 kHz 20 21 22 24 24 25 27 27
below BW125 RAL_STATUS_UNKNOWN_VALUE
followed by a symbol-count correction: -1 at 4 symbols, -2 at 8 or 16, since
more looks at the same correlation reach the same detection quality at a lower
threshold. We run 4 symbols everywhere and applied no such correction.
The error this leaves is mild on this family -- 1-3 counts per octave of
bandwidth -- which is why SF+13 survived so long. It is not nil: against the
BW500 column SF+13 is ten counts too sensitive at SF12, and `set bw` accepts
250 and 500. Contrast the LR11xx, where the same omission costs ~12 counts per
octave and drove field units onto the offset rail.
Below BW125 Semtech declines to tabulate, and BW62.5 is our default preset, so
that gap is where we normally operate. SF+13 is kept there, and it is not a
guess: it sits ~1 count below Semtech's BW125 column at every SF, which is the
correct direction for a narrower bandwidth, and a field SX1262 at SF7/BW62.5
converged to detPeak 19 against this table's 20 -- one rung of adaptive
correction. SF+13 is also already a 4-symbol figure (RadioLib programs it with
CAD_ON_4_SYMB citing DS rev 1.1 p.92), so the symbol correction must not be
applied to it a second time. Net effect: no behaviour change at the default
preset, and a real table where there was none at BW250/500.
The clamp around the adaptive offset moves from 15-40 to SX126X_CAD_PEAK_MIN/
MAX (12-48) and is now exported through sx126x_cad_peak_min/max(). Both halves
matter. The ceiling has to cover the widest-band base (34 at SF12/BW500 with 4
symbols) plus the full +12 offset excursion, which 40 did not. The floor stops
two counts above cadDetMin, pinned at 10 everywhere -- a detPeak at or below the
correlator's own noise-estimate floor expresses no threshold at all. Exporting
it is what stops the C++ staircase exploring offsets that collapse onto one
peak and reading the sampling noise between identical configurations as
curvature; that failure mode is documented on the LR2021 and was observed on
the LR1110.
sx126x_cad_base_peak_cfg() is the single source of truth so sx126x_do_cad(),
the exported sx126x_cad_base_peak() and sx126x_cad_probe() cannot drift: the
base is what `get cad` prints and what the staircase offsets from, so a base
disagreeing with the peak actually programmed would make every rung a lie.
== Why this is one patch ==
Five of the sections above shipped as separate files (0011 band-rssi-cal, 0012
@@ -503,10 +553,10 @@ Regenerate with:
appended to this preamble.
diff --git a/drivers/lora/native/sx126x/sx126x.c b/drivers/lora/native/sx126x/sx126x.c
index 30243ba5dc7..0e870e37468 100644
index 30243ba5dc7..aa0732b1de9 100644
--- a/drivers/lora/native/sx126x/sx126x.c
+++ b/drivers/lora/native/sx126x/sx126x.c
@@ -6,72 +6,218 @@
@@ -6,72 +6,220 @@
#include <zephyr/kernel.h>
#include <zephyr/device.h>
#include <zephyr/drivers/lora.h>
@@ -667,15 +717,17 @@ index 30243ba5dc7..0e870e37468 100644
+}
+
+/* Reset all software state that indicates "we are currently receiving":
+ * the rx_packet_active latch (and its deadline timestamp) and the
+ * preamble-grace timestamp. Paired write so the fields never drift out of
+ * sync. Called from every RX (re)start site, every terminal-event handler
+ * (RX_DONE / CRC_ERR / RX_TX_TIMEOUT), and on TX-state entry. */
+ * the rx_packet_active latch (and its deadline timestamp), the
+ * preamble-grace timestamp and the raw-HEADER_VALID deadline. Paired write
+ * so the fields never drift out of sync. Called from every RX (re)start
+ * site, every terminal-event handler (RX_DONE / CRC_ERR / RX_TX_TIMEOUT),
+ * and on TX-state entry. */
+static inline void sx126x_reset_rx_busy_signals(struct sx126x_data *data)
+{
+ data->rx_packet_active = false;
+ atomic_set(&data->preamble_seen_at_ms, 0);
+ atomic_set(&data->header_seen_at_ms, 0);
+ atomic_set(&data->raw_header_seen_at_ms, 0);
+}
+
+/* Grace period for the PREAMBLE_DETECTED -> HEADER_VALID gap, SF/BW-aware.
@@ -749,7 +801,7 @@ index 30243ba5dc7..0e870e37468 100644
}
static bool should_enable_ldro(enum lora_datarate sf, enum lora_signal_bandwidth bw,
@@ -81,7 +227,11 @@ static bool should_enable_ldro(enum lora_datarate sf, enum lora_signal_bandwidth
@@ -81,7 +229,11 @@ static bool should_enable_ldro(enum lora_datarate sf, enum lora_signal_bandwidth
return true;
}
@@ -762,7 +814,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Symbol time = 2^SF / BW (in seconds) */
/* 16.38 ms = 16380 us */
/* 2^SF / BW > 0.01638 => 2^SF * 1000000 / BW > 16380 */
@@ -216,12 +366,43 @@ static int sx126x_set_modulation_params(const struct device *dev,
@@ -216,12 +368,43 @@ static int sx126x_set_modulation_params(const struct device *dev,
return sx126x_hal_write_cmd(dev, SX126X_CMD_SET_MODULATION_PARAMS, buf, 4);
}
@@ -806,7 +858,7 @@ index 30243ba5dc7..0e870e37468 100644
sys_put_be16(preamble_len, &buf[0]);
buf[2] = header_type;
@@ -229,7 +410,31 @@ static int sx126x_set_packet_params(const struct device *dev,
@@ -229,7 +412,31 @@ static int sx126x_set_packet_params(const struct device *dev,
buf[4] = crc_mode;
buf[5] = invert_iq;
@@ -839,7 +891,7 @@ index 30243ba5dc7..0e870e37468 100644
}
static int sx126x_set_sync_word(const struct device *dev, bool public_network)
@@ -243,10 +448,128 @@ static int sx126x_set_sync_word(const struct device *dev, bool public_network)
@@ -243,10 +450,128 @@ static int sx126x_set_sync_word(const struct device *dev, bool public_network)
return sx126x_hal_write_regs(dev, SX126X_REG_LORA_SYNC_WORD_MSB, buf, 2);
}
@@ -970,7 +1022,7 @@ index 30243ba5dc7..0e870e37468 100644
return sx126x_hal_write_regs(dev, SX126X_REG_RX_GAIN, &val, 1);
}
@@ -296,7 +619,7 @@ static int sx126x_get_packet_status(const struct device *dev,
@@ -296,7 +621,7 @@ static int sx126x_get_packet_status(const struct device *dev,
uint8_t buf[3];
int ret;
@@ -979,7 +1031,7 @@ index 30243ba5dc7..0e870e37468 100644
if (ret == 0) {
/* RSSI is -value/2 dBm */
*rssi = -((int16_t)buf[0] >> 1);
@@ -307,6 +630,140 @@ static int sx126x_get_packet_status(const struct device *dev,
@@ -307,6 +632,140 @@ static int sx126x_get_packet_status(const struct device *dev,
return ret;
}
@@ -1120,7 +1172,7 @@ index 30243ba5dc7..0e870e37468 100644
static int sx126x_chip_init(const struct device *dev)
{
const struct sx126x_hal_config *config = dev->config;
@@ -367,6 +824,26 @@ static int sx126x_chip_init(const struct device *dev)
@@ -367,6 +826,26 @@ static int sx126x_chip_init(const struct device *dev)
return ret;
}
@@ -1147,7 +1199,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Set packet type to LoRa */
ret = sx126x_set_packet_type(dev, SX126X_PACKET_TYPE_LORA);
if (ret < 0) {
@@ -374,10 +851,23 @@ static int sx126x_chip_init(const struct device *dev)
@@ -374,10 +853,23 @@ static int sx126x_chip_init(const struct device *dev)
return ret;
}
@@ -1174,7 +1226,7 @@ index 30243ba5dc7..0e870e37468 100644
if (ret < 0) {
LOG_ERR("Set IRQ params failed: %d", ret);
return ret;
@@ -390,6 +880,10 @@ static int sx126x_chip_init(const struct device *dev)
@@ -390,6 +882,10 @@ static int sx126x_chip_init(const struct device *dev)
return ret;
}
@@ -1185,7 +1237,7 @@ index 30243ba5dc7..0e870e37468 100644
LOG_INF("SX126x initialized");
return 0;
}
@@ -398,15 +892,44 @@ static void sx126x_dio1_callback(const struct device *dev)
@@ -398,15 +894,44 @@ static void sx126x_dio1_callback(const struct device *dev)
{
struct sx126x_data *data = dev->data;
@@ -1232,7 +1284,7 @@ index 30243ba5dc7..0e870e37468 100644
sx126x_hal_set_rf_switch(dev, enable, tx);
}
}
@@ -426,6 +949,7 @@ static void sx126x_disconnect_rf_gpios(const struct device *dev)
@@ -426,6 +951,7 @@ static void sx126x_disconnect_rf_gpios(const struct device *dev)
sx126x_disconnect_gpio(&config->antenna_enable);
sx126x_disconnect_gpio(&config->tx_enable);
sx126x_disconnect_gpio(&config->rx_enable);
@@ -1240,7 +1292,7 @@ index 30243ba5dc7..0e870e37468 100644
}
static int sx126x_reconnect_rf_gpios(const struct device *dev)
@@ -451,10 +975,238 @@ static int sx126x_reconnect_rf_gpios(const struct device *dev)
@@ -451,10 +977,238 @@ static int sx126x_reconnect_rf_gpios(const struct device *dev)
return ret;
}
@@ -1479,7 +1531,7 @@ index 30243ba5dc7..0e870e37468 100644
static int sx126x_set_sleep(const struct device *dev)
{
struct sx126x_data *data = dev->data;
@@ -533,8 +1285,16 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
@@ -533,8 +1287,16 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
struct sx126x_data *data = dev->data;
struct sx126x_rx_result result = { 0 };
uint8_t payload_len = 0, offset = 0;
@@ -1496,7 +1548,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Get received packet info */
ret = sx126x_get_rx_buffer_status(dev, &payload_len, &offset);
if (ret < 0) {
@@ -544,9 +1304,26 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
@@ -544,9 +1306,26 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
/* Get signal quality */
sx126x_get_packet_status(dev, &result.rssi, &result.snr);
@@ -1526,7 +1578,7 @@ index 30243ba5dc7..0e870e37468 100644
result.status = -EIO;
} else {
/* Read payload into shared buffer */
@@ -564,23 +1341,55 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
@@ -564,23 +1343,55 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
}
}
@@ -1595,7 +1647,7 @@ index 30243ba5dc7..0e870e37468 100644
sx126x_set_sleep(dev);
k_msgq_put(&data->rx_msgq, &result, K_NO_WAIT);
}
@@ -589,8 +1398,83 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
@@ -589,8 +1400,83 @@ static void sx126x_handle_irq_rx_done(const struct device *dev, uint16_t irq_sta
static void sx126x_handle_irq_timeout(const struct device *dev)
{
struct sx126x_data *data = dev->data;
@@ -1679,7 +1731,7 @@ index 30243ba5dc7..0e870e37468 100644
sx126x_set_sleep(dev);
if (data->tx_async_signal != NULL) {
@@ -633,10 +1517,54 @@ static void sx126x_irq_work_handler(struct k_work *work)
@@ -633,10 +1519,54 @@ static void sx126x_irq_work_handler(struct k_work *work)
sx126x_handle_irq_rx_done(dev, irq_status);
}
@@ -1734,7 +1786,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Re-enable the DIO1 interrupt for the next event (unless sleeping) */
if (atomic_get(&data->state) != SX126X_REST_STATE) {
sx126x_hal_dio1_irq_enable(dev);
@@ -648,6 +1576,7 @@ static int sx126x_lora_config(const struct device *dev,
@@ -648,6 +1578,7 @@ static int sx126x_lora_config(const struct device *dev,
{
struct sx126x_data *data = dev->data;
const struct sx126x_hal_config *hal_config = dev->config;
@@ -1742,7 +1794,7 @@ index 30243ba5dc7..0e870e37468 100644
bool ldro;
int ret;
@@ -679,25 +1608,45 @@ static int sx126x_lora_config(const struct device *dev,
@@ -679,25 +1610,45 @@ static int sx126x_lora_config(const struct device *dev,
goto out;
}
@@ -1790,7 +1842,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Set sync word */
ret = sx126x_set_sync_word(dev, config->public_network);
if (ret < 0) {
@@ -721,6 +1670,10 @@ out:
@@ -721,6 +1672,10 @@ out:
return ret;
}
@@ -1801,7 +1853,7 @@ index 30243ba5dc7..0e870e37468 100644
static int sx126x_lora_send_async(const struct device *dev,
uint8_t *data_buf, uint32_t data_len,
struct k_poll_signal *async)
@@ -738,11 +1691,27 @@ static int sx126x_lora_send_async(const struct device *dev,
@@ -738,11 +1693,27 @@ static int sx126x_lora_send_async(const struct device *dev,
return -EINVAL;
}
@@ -1831,7 +1883,7 @@ index 30243ba5dc7..0e870e37468 100644
k_mutex_lock(&data->lock, K_FOREVER);
ret = sx126x_ensure_ready(dev);
@@ -752,6 +1721,59 @@ static int sx126x_lora_send_async(const struct device *dev,
@@ -752,6 +1723,59 @@ static int sx126x_lora_send_async(const struct device *dev,
return ret;
}
@@ -1891,7 +1943,7 @@ index 30243ba5dc7..0e870e37468 100644
data->tx_async_signal = async;
k_msgq_purge(&data->tx_msgq);
@@ -777,8 +1799,99 @@ static int sx126x_lora_send_async(const struct device *dev,
@@ -777,8 +1801,99 @@ static int sx126x_lora_send_async(const struct device *dev,
/* Enable antenna and set TX path */
sx126x_set_rf_path(dev, true, true);
@@ -1993,7 +2045,7 @@ index 30243ba5dc7..0e870e37468 100644
if (ret < 0) {
goto out_error;
}
@@ -847,6 +1960,8 @@ static int sx126x_lora_recv(const struct device *dev, uint8_t *data_buf,
@@ -847,6 +1962,8 @@ static int sx126x_lora_recv(const struct device *dev, uint8_t *data_buf,
}
data->rx_cb = NULL;
@@ -2002,7 +2054,7 @@ index 30243ba5dc7..0e870e37468 100644
k_msgq_purge(&data->rx_msgq);
/* Set packet parameters for variable length reception */
@@ -918,6 +2033,8 @@ static int sx126x_lora_recv_async(const struct device *dev,
@@ -918,6 +2035,8 @@ static int sx126x_lora_recv_async(const struct device *dev,
/* Stop async reception */
data->rx_cb = NULL;
data->rx_cb_user_data = NULL;
@@ -2011,7 +2063,7 @@ index 30243ba5dc7..0e870e37468 100644
if (atomic_cas(&data->state, SX126X_STATE_RX, SX126X_STATE_IDLE)) {
sx126x_set_standby(dev, SX126X_STANDBY_RC);
sx126x_set_sleep(dev);
@@ -932,6 +2049,19 @@ static int sx126x_lora_recv_async(const struct device *dev,
@@ -932,6 +2051,19 @@ static int sx126x_lora_recv_async(const struct device *dev,
return -EINVAL;
}
@@ -2031,7 +2083,7 @@ index 30243ba5dc7..0e870e37468 100644
if (!atomic_cas(&data->state, SX126X_REST_STATE, SX126X_STATE_RX)) {
LOG_ERR("Busy");
k_mutex_unlock(&data->lock);
@@ -945,8 +2075,18 @@ static int sx126x_lora_recv_async(const struct device *dev,
@@ -945,8 +2077,18 @@ static int sx126x_lora_recv_async(const struct device *dev,
return ret;
}
@@ -2050,7 +2102,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Set packet parameters */
ret = sx126x_set_packet_params(dev,
@@ -959,6 +2099,7 @@ static int sx126x_lora_recv_async(const struct device *dev,
@@ -959,6 +2101,7 @@ static int sx126x_lora_recv_async(const struct device *dev,
SX126X_LORA_IQ_INVERTED : SX126X_LORA_IQ_STANDARD);
if (ret < 0) {
data->rx_cb = NULL;
@@ -2058,7 +2110,7 @@ index 30243ba5dc7..0e870e37468 100644
sx126x_set_sleep(dev);
k_mutex_unlock(&data->lock);
return ret;
@@ -971,11 +2112,21 @@ static int sx126x_lora_recv_async(const struct device *dev,
@@ -971,11 +2114,21 @@ static int sx126x_lora_recv_async(const struct device *dev,
ret = sx126x_set_rx(dev, 0);
if (ret < 0) {
data->rx_cb = NULL;
@@ -2080,7 +2132,7 @@ index 30243ba5dc7..0e870e37468 100644
k_mutex_unlock(&data->lock);
return 0;
}
@@ -993,7 +2144,9 @@ static uint32_t sx126x_lora_airtime(const struct device *dev, uint32_t data_len)
@@ -993,7 +2146,9 @@ static uint32_t sx126x_lora_airtime(const struct device *dev, uint32_t data_len)
}
/* Calculate symbol time in microseconds */
@@ -2091,7 +2143,7 @@ index 30243ba5dc7..0e870e37468 100644
sf = data->config.datarate;
/* Symbol time = 2^SF / BW (seconds) */
@@ -1051,7 +2204,7 @@ static int sx126x_lora_test_cw(const struct device *dev, uint32_t frequency,
@@ -1051,7 +2206,7 @@ static int sx126x_lora_test_cw(const struct device *dev, uint32_t frequency,
/* Set PA config and TX power */
ret = sx126x_hal_configure_tx_params(dev, tx_power, frequency,
@@ -2100,7 +2152,7 @@ index 30243ba5dc7..0e870e37468 100644
if (ret < 0) {
sx126x_set_sleep(dev);
k_mutex_unlock(&data->lock);
@@ -1083,14 +2236,855 @@ static int sx126x_lora_test_cw(const struct device *dev, uint32_t frequency,
@@ -1083,14 +2238,983 @@ static int sx126x_lora_test_cw(const struct device *dev, uint32_t frequency,
return 0;
}
@@ -2189,11 +2241,50 @@ index 30243ba5dc7..0e870e37468 100644
+
+ sx126x_get_irq_status(dev, &irq_status);
+
+ /* HEADER_VALID raw bit: narrow window between DIO1 firing and the work
+ * handler running. Latch will take over within microseconds. */
+ /* HEADER_VALID raw bit, bounded. Normally this is just the narrow
+ * window between DIO1 firing and the work handler running, and the
+ * latch above takes over within microseconds -- but that holds only
+ * while DIO1 interrupts are actually arriving. If they stop (a
+ * stalled work queue, or an SoC returning from light sleep with the
+ * pad no longer routed to the GPIO matrix) the handler never runs, the
+ * chip's sticky IRQ bits are never cleared, and rx_packet_active is
+ * never set -- so the bounded latch path above is never reached and
+ * every poll lands here instead. An unbounded "return true" then
+ * mutes TX until something else intervenes, which in practice means
+ * the Dispatcher's 4 s CAD-timeout recovery: every single transmit
+ * costs 4 s and the node looks like a dying radio rather than a
+ * driver that stopped being interrupted.
+ *
+ * Same deadline as the latch, for the same reason -- releasing early
+ * would let TX start on top of a packet that is still arriving. This
+ * is a stuck-state safety net, not a timing mechanism. */
+ if (irq_status & SX126X_IRQ_HEADER_VALID) {
+ uint32_t now = k_uptime_get_32();
+ uint32_t seen = (uint32_t)atomic_get(&data->raw_header_seen_at_ms);
+
+ if (seen == 0) {
+ /* First observation in this RX cycle. Use 1 as the
+ * "I am set" sentinel if k_uptime returns 0 at boot. */
+ atomic_set(&data->raw_header_seen_at_ms,
+ (atomic_val_t)(now == 0 ? 1U : now));
+ k_mutex_unlock(&data->lock);
+ return true;
+ }
+ if ((now - seen) < sx126x_max_payload_ms(data)) {
+ k_mutex_unlock(&data->lock);
+ return true;
+ }
+ LOG_WRN("HEADER_VALID stuck %u ms with no work handler "
+ "(DIO1 not arriving?), releasing TX gate",
+ now - seen);
+ /* Drop the sticky reception bits so the next poll starts clean. */
+ sx126x_clear_irq_status(dev, SX126X_IRQ_PREAMBLE_DETECTED |
+ SX126X_IRQ_SYNC_WORD_VALID |
+ SX126X_IRQ_HEADER_VALID |
+ SX126X_IRQ_HEADER_ERR);
+ sx126x_reset_rx_busy_signals(data);
+ k_mutex_unlock(&data->lock);
+ return true;
+ return false;
+ }
+
+ /* PREAMBLE_DETECTED with SF-aware grace. PREAMBLE_DETECTED is masked
@@ -2238,6 +2329,7 @@ index 30243ba5dc7..0e870e37468 100644
+ /* No preamble bit, no header bit: nothing in flight. Defensive
+ * reset in case a stale timestamp survived a mode change. */
+ atomic_set(&data->preamble_seen_at_ms, 0);
+ atomic_set(&data->raw_header_seen_at_ms, 0);
+ k_mutex_unlock(&data->lock);
+ return false;
+}
@@ -2457,14 +2549,103 @@ index 30243ba5dc7..0e870e37468 100644
+ * chip-family-specific: LR11xx wants ~48-68 for the same job -- never
+ * copy values across families (56-68 here once made CAD near-blind and
+ * the LBT gate inert). */
+static uint8_t sx126x_cad_detect_peak(uint8_t sf)
+/* Recommended cadDetPeak. The datasheet gives no table (rev 2.2 §13.4.7 only
+ * says the values "must be carefully tested" and defers to AN1200.48, which is
+ * paywalled), so the numbers come from Semtech's own reference stack: LoRa
+ * Basics Modem v4.9.0, ral_sx126x.c ral_sx126x_get_lora_cad_det_peak().
+ *
+ * Bandwidth matters, and it did not used to be considered here at all. It is a
+ * mild effect on this family — 1-3 counts per octave, against ~12 on the LR11xx
+ * — which is why a flat SF+13 survived so long. But Semtech's BW500 column
+ * runs up to 35 at SF12 where SF+13 gives 25: ten counts too sensitive on a
+ * wide-band preset, and `set bw` accepts 250 and 500.
+ *
+ * Below BW125 Semtech returns RAL_STATUS_UNKNOWN_VALUE. Our default preset is
+ * BW62.5, so that gap is where we normally live, and there we keep SF+13 — it
+ * is not a guess: it sits ~1 count below Semtech's BW125 column at every SF,
+ * which is the correct direction for a narrower bandwidth, and it is confirmed
+ * on hardware. A field SX1262 at SF7/BW62.5 converged to detPeak 19 against
+ * this table's 20, i.e. the adaptive controller moved it a single rung. Note
+ * SF+13 is already a 4-symbol figure (RadioLib programs it with CAD_ON_4_SYMB,
+ * citing DS rev 1.1 p.92), so the symbol correction below must NOT be applied
+ * to it a second time. */
+static uint8_t sx126x_cad_detect_peak(uint8_t sf, uint32_t bw_hz, uint8_t symb_nb)
+{
+ /* SF5 SF6 SF7 SF8 SF9 SF10 SF11 SF12 */
+ static const uint8_t bw500[8] = { 22, 23, 25, 26, 30, 31, 33, 35 };
+ static const uint8_t bw125[8] = { 20, 21, 22, 24, 24, 25, 27, 27 };
+ int peak;
+
+ if (sf < 5) {
+ sf = 5;
+ } else if (sf > 12) {
+ sf = 12;
+ }
+ return sf + 13;
+
+ /* Narrower than BW125: Semtech offers nothing, SF+13 is measured. */
+ if (bw_hz < 125000U) {
+ return sf + 13;
+ }
+
+ /* Semtech brackets only >=500 and >=125 on this family — BW250 shares
+ * the BW125 column, unlike the LR11xx which gives it its own. */
+ peak = (int)(bw_hz >= 500000U ? bw500[sf - 5] : bw125[sf - 5]);
+
+ /* More symbols means more looks at the same correlation, so the same
+ * detection quality is reached at a lower threshold. We run 4 symbols
+ * everywhere (LORA_CAD_SYMB_4 in LoRaRadioBase::buildModemConfig). */
+ if (symb_nb >= 8) {
+ peak -= 2;
+ } else if (symb_nb >= 4) {
+ peak -= 1;
+ }
+
+ return (uint8_t)peak;
+}
+
+/* The detPeak range this driver will actually program. Exported through
+ * sx126x_cad_peak_min/max() so the C++ adaptive-CAD controller can narrow its
+ * offset window to match: where base+offset falls outside this, several offsets
+ * collapse onto one peak and the staircase reads sampling noise between
+ * identical configurations as curvature.
+ *
+ * The ceiling covers the widest-band base (34 at SF12/BW500 with 4 symbols)
+ * plus the full CAD_LEVEL_MAX excursion of +12. The floor stops two counts
+ * above cadDetMin, which is pinned at 10 everywhere: a detPeak at or below the
+ * correlator's own noise-estimate floor does not express a threshold at all.
+ * At the most sensitive base (18, SF5 narrow-band) that does clip the bottom
+ * rungs of the offset window — which is exactly why it is exported rather than
+ * applied silently. */
+#define SX126X_CAD_PEAK_MIN 12
+#define SX126X_CAD_PEAK_MAX 48
+
+uint8_t sx126x_cad_peak_min(void)
+{
+ return SX126X_CAD_PEAK_MIN;
+}
+
+uint8_t sx126x_cad_peak_max(void)
+{
+ return SX126X_CAD_PEAK_MAX;
+}
+
+/* Single source of truth for the base peak, so sx126x_do_cad(), the exported
+ * sx126x_cad_base_peak() and sx126x_cad_probe() cannot drift apart. A base
+ * that disagreed with the peak actually programmed would make every rung the
+ * C++ staircase reasons about a lie.
+ *
+ * An unresolvable bandwidth falls through to the sub-125 branch, i.e. SF+13,
+ * which is what this driver did unconditionally before the table existed. */
+static uint8_t sx126x_cad_base_peak_cfg(struct lora_modem_config *mc)
+{
+ uint32_t bw_hz;
+ uint8_t symb_nb = mc->cad.symbol_num ? (uint8_t)mc->cad.symbol_num : 2;
+
+ if (bandwidth_to_hz(mc->bandwidth, &bw_hz) < 0) {
+ bw_hz = 0;
+ }
+
+ return sx126x_cad_detect_peak((uint8_t)mc->datarate, bw_hz, symb_nb);
+}
+
+/* Blocking-CAD wait budget scaled to the actual CAD duration:
@@ -2494,13 +2675,12 @@ index 30243ba5dc7..0e870e37468 100644
+{
+ struct lora_modem_config *mc = &data->config;
+ uint8_t sf = (uint8_t)mc->datarate;
+ uint8_t symb_nb = 2;
+ uint8_t detect_peak = sx126x_cad_detect_peak(sf);
+ /* Both the table lookup and the timeout need the symbol count, so it is
+ * resolved before the base peak rather than after it. */
+ uint8_t symb_nb = mc->cad.symbol_num ? (uint8_t)mc->cad.symbol_num : 2;
+ uint8_t detect_peak = sx126x_cad_base_peak_cfg(mc);
+ int ret;
+
+ if (mc->cad.symbol_num != 0) {
+ symb_nb = (uint8_t)mc->cad.symbol_num;
+ }
+ if (mc->cad.detection_peak != 0) {
+ detect_peak = mc->cad.detection_peak;
+ } else if (data->cad_peak_offset != 0) {
@@ -2508,10 +2688,10 @@ index 30243ba5dc7..0e870e37468 100644
+ * Clamped to a sane absolute window around the family scale. */
+ int peak = (int)detect_peak + data->cad_peak_offset;
+
+ if (peak < 15) {
+ peak = 15;
+ } else if (peak > 40) {
+ peak = 40;
+ if (peak < SX126X_CAD_PEAK_MIN) {
+ peak = SX126X_CAD_PEAK_MIN;
+ } else if (peak > SX126X_CAD_PEAK_MAX) {
+ peak = SX126X_CAD_PEAK_MAX;
+ }
+ detect_peak = (uint8_t)peak;
+ }
@@ -2677,7 +2857,7 @@ index 30243ba5dc7..0e870e37468 100644
+{
+ struct sx126x_data *data = dev->data;
+
+ return sx126x_cad_detect_peak((uint8_t)data->config.datarate);
+ return sx126x_cad_base_peak_cfg(&data->config);
+}
+
+int sx126x_cad_probe(const struct device *dev, int8_t peak_offset)
@@ -2687,10 +2867,10 @@ index 30243ba5dc7..0e870e37468 100644
+ int peak = base + peak_offset;
+ int ret;
+
+ if (peak < 15) {
+ peak = 15;
+ } else if (peak > 40) {
+ peak = 40;
+ if (peak < SX126X_CAD_PEAK_MIN) {
+ peak = SX126X_CAD_PEAK_MIN;
+ } else if (peak > SX126X_CAD_PEAK_MAX) {
+ peak = SX126X_CAD_PEAK_MAX;
+ }
+
+ /* One-shot absolute override consumed by sx126x_do_cad(). Probes and
@@ -2963,7 +3143,7 @@ index 30243ba5dc7..0e870e37468 100644
};
#ifdef CONFIG_PM_DEVICE
@@ -1112,6 +3106,7 @@ static int sx126x_pm_action(const struct device *dev,
@@ -1112,6 +3236,7 @@ static int sx126x_pm_action(const struct device *dev,
static int sx126x_init(const struct device *dev)
{
struct sx126x_data *data = dev->data;
@@ -2971,7 +3151,7 @@ index 30243ba5dc7..0e870e37468 100644
int ret;
/* Initialize data structures */
@@ -1121,9 +3116,33 @@ static int sx126x_init(const struct device *dev)
@@ -1121,9 +3246,33 @@ static int sx126x_init(const struct device *dev)
k_msgq_init(&data->rx_msgq, (char *)&data->rx_result,
sizeof(struct sx126x_rx_result), 1);
k_work_init(&data->irq_work, sx126x_irq_work_handler);
@@ -3005,7 +3185,7 @@ index 30243ba5dc7..0e870e37468 100644
/* Initialize HAL */
ret = sx126x_hal_init(dev);
@@ -1185,6 +3204,8 @@ static int sx126x_init(const struct device *dev)
@@ -1185,6 +3334,8 @@ static int sx126x_init(const struct device *dev)
{0}), \
.rx_enable = GPIO_DT_SPEC_INST_GET_OR(inst, rx_enable_gpios, \
{0}), \
@@ -3014,7 +3194,7 @@ index 30243ba5dc7..0e870e37468 100644
.dio2_tx_enable = DT_INST_PROP(inst, dio2_tx_enable), \
.dio3_tcxo_enable = DT_INST_NODE_HAS_PROP(inst, dio3_tcxo_voltage), \
.dio3_tcxo_voltage = DT_INST_PROP_OR(inst, dio3_tcxo_voltage, 0), \
@@ -1239,6 +3260,8 @@ DT_INST_FOREACH_STATUS_OKAY_VARGS(SX126X_INIT, true)
@@ -1239,6 +3390,8 @@ DT_INST_FOREACH_STATUS_OKAY_VARGS(SX126X_INIT, true)
{0}), \
.rx_enable = GPIO_DT_SPEC_INST_GET_OR(inst, rx_enable_gpios, \
{0}), \
@@ -3024,10 +3204,10 @@ index 30243ba5dc7..0e870e37468 100644
.dio3_tcxo_enable = DT_INST_NODE_HAS_PROP(inst, dio3_tcxo_voltage), \
.dio3_tcxo_voltage = DT_INST_PROP_OR(inst, dio3_tcxo_voltage, 0), \
diff --git a/drivers/lora/native/sx126x/sx126x.h b/drivers/lora/native/sx126x/sx126x.h
index 9dbf3f26586..675f3eca8a7 100644
index 9dbf3f26586..51fb808bb46 100644
--- a/drivers/lora/native/sx126x/sx126x.h
+++ b/drivers/lora/native/sx126x/sx126x.h
@@ -56,13 +56,107 @@ struct sx126x_data {
@@ -56,13 +56,121 @@ struct sx126x_data {
/* Async RX callback */
lora_recv_cb rx_cb;
void *rx_cb_user_data;
@@ -3092,6 +3272,20 @@ index 9dbf3f26586..675f3eca8a7 100644
+ * the latch once sx126x_max_payload_ms() has elapsed. */
+ atomic_t header_seen_at_ms;
+
+ /* Timestamp (k_uptime_get_32() units, ms) of the first observation of a
+ * raw HEADER_VALID bit by sx126x_is_receiving() while rx_packet_active
+ * is still false -- i.e. DIO1 fired but the work handler has not yet
+ * promoted the latch. Zero means "not tracking".
+ *
+ * That handoff normally takes microseconds, so this exists only to bound
+ * the case where it never happens because DIO1 interrupts have stopped
+ * arriving at all. Nothing then clears the chip's sticky IRQ bits, and
+ * rx_packet_active is never set, so header_seen_at_ms above cannot bound
+ * anything -- without this field the TX gate stays true until the
+ * Dispatcher's 4 s CAD-timeout recovery clears it, once per packet.
+ * Reset together with the other RX-busy signals. */
+ atomic_t raw_header_seen_at_ms;
+
+ uint32_t dc_rx_time; /* stored duty cycle rx period (15.625us steps) */
+ uint32_t dc_sleep_time; /* stored duty cycle sleep period (15.625us steps) */
+