diff --git a/src/main.cpp b/src/main.cpp index 97029452..94f4ea19 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -1761,11 +1761,6 @@ void setup() { setup_ui_manager(); BOOT_PROFILE_END("ui_manager"); - // Confirm app0 as soon as the persistent store, LXMF router, and UI have - // all initialized successfully. Do not defer this behind announces or - // callback setup: a reset after this point must not roll back to app1. - confirm_running_firmware(); - // Now that UIManager has built screens and configured the active // one, start the LVGL render task. Doing this any earlier means // the LVGL task refreshes its empty default screen on top of the @@ -1782,6 +1777,14 @@ void setup() { } INFO("LVGL task started on core 1"); + // Confirm app0 only after the persistent store, LXMF router, UI, and its + // render task have all initialized successfully. Starting the task is the + // final fallible boot gate; validating the image before it succeeds would + // strand the device on an image that can never present a usable UI. + // Announcements and callback registration remain outside the rollback + // gate because they are recoverable runtime operations. + confirm_running_firmware(); + // Send initial LXST voice destination announce if (ui_manager) { ui_manager->announce_lxst(); diff --git a/tests/build_scripts/test_message_persistence_contract.py b/tests/build_scripts/test_message_persistence_contract.py index f9cff29a..6a229ac7 100644 --- a/tests/build_scripts/test_message_persistence_contract.py +++ b/tests/build_scripts/test_message_persistence_contract.py @@ -111,7 +111,8 @@ def test_successful_boot_cancels_ota_rollback_after_subsystems_initialize(): assert "esp_ota_mark_app_valid_cancel_rollback()" in confirm setup = function_body(source, "void setup()", "void loop()") assert setup.index("setup_lxmf();") < setup.index("setup_ui_manager();") - assert setup.index("setup_ui_manager();") < setup.index("confirm_running_firmware();") + assert setup.index("setup_ui_manager();") < setup.index("LVGLInit::start_task") + assert setup.index("LVGLInit::start_task") < setup.index("confirm_running_firmware();") def test_system_info_reports_littlefs_not_unmounted_spiffs():