#415: a Lua app was covered by the app drawer whenever a message arrived. Reported by jadestarwatcher, reproduced by mysterywavi, both on T-Deck. Mine, from the #393 badge fix. Apps launched from the drawer deliberately leave it alive underneath (appTileCb says so outright), and my badge refresh rebuilt it on every unread-count change, with openAppDrawer() ending in a move_foreground that threw it on top of the running app. The refresh now runs only when nothing is drawn in front of the drawer, tested by sibling order rather than by listing the tools, so a tool added later is covered without anyone remembering to update a list. The status bar is excluded, since it legitimately floats above the drawer at all times and treating it as covering would have stopped the badges refreshing at all. Leaving the signature stale is what makes it self-healing: the check runs again each tick, so the count is right by the time the drawer is back in front, with no need to hook every close path. Scroll position is now preserved across the rebuild too, which my change had also been resetting. #410: on the M9 the accent variants appeared but could not be selected. Also mine, from the #387 work. The picker was handled below m9HandleArrowKey, which takes LEFT and RIGHT for the caret and returns, so the arrows never reached it: the box was drawn and nothing could touch it. Lifted above that call, as its own function rather than a second copy of the logic. #399, requested by @Danie10: an option to advertise a position near you rather than your address. Settings, GPS, cycling exact / 100 m / 250 m / 1 km. The displacement is derived from the node identity, so it is the same offset every time. That is the whole point rather than an implementation detail: a fresh random offset per advert would scatter points around the true position, and averaging a night of them would recover the centre exactly. A fixed displacement instead looks like a node that sits somewhere else, which is what a manually set location already looks like. It applies only to our own adverts; the map and the GPS page keep the real fix, because the aim is to tell other people less, not to lie to yourself. Schema v57. The host test caught the new field the moment it was added, which is what it is for. All nine S3 envs and both ESP32-P4 targets green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
wadamesh.com infrastructure
Distribution stack for wadamesh: a VPS nginx origin behind Cloudflare.
tiles.wadamesh.com →CF (HTTP, edge-cached) → nginx → OpenStreetMap / OpenTopoMap
firmware.wadamesh.com →CF (cache bins) → nginx → /srv/wadamesh/firmware
flasher.wadamesh.com →CF (HTTPS) → 301 → wadamesh.com
wadamesh.com →CF (HTTPS) → nginx → /srv/wadamesh/site
Map tile styles. The default /{z}/{x}/{y}.jpg route serves OpenStreetMap
(the firmware default). An opt-in OpenTopoMap topographic style is served from
/opentopo/{z}/{x}/{y}.jpg (explicit OSM alias at /osm/...); the device requests
it only when the user enables Map → Options → Topographic map. Legal: OpenTopoMap
map tiles are © OpenTopoMap (CC-BY-SA) over © OpenStreetMap contributors
(ODbL) + SRTM — the touch UI shows that attribution when topo is active, and the
14-day disk cache keeps each tile hitting OpenTopoMap at most once per fortnight
(their tile-usage policy asks for a contactable UA + caching, both of which the
transcode service provides). Deploying the topo routes = update
tiles.wadamesh.com.conf + tile-transcode.py, then
systemctl restart wadamesh-tile-transcode && nginx -t && systemctl reload nginx
and purge the Cloudflare cache for tiles.wadamesh.com/opentopo/*.
The firmware fetches tiles + the update-check over plain HTTP (on-device HTTPS isn't viable — mbedTLS needs ~30 KB heap, only ~5 KB is free post-Wi-Fi), so the tile + firmware hosts must stay reachable over HTTP. Cloudflare provides the edge cache, HTTPS for the flasher, and hides the origin IP (so no IP lives in this repo or the firmware).
1. VPS (origin)
sudo apt install nginx
sudo mkdir -p /srv/wadamesh/firmware/releases/TOUCH /var/cache/nginx/wadamesh-tiles
sudo cp deploy/nginx/tiles.wadamesh.com.conf /etc/nginx/sites-available/
sudo cp deploy/nginx/firmware.wadamesh.com.conf /etc/nginx/sites-available/
sudo ln -s /etc/nginx/sites-available/tiles.wadamesh.com.conf /etc/nginx/sites-enabled/
sudo ln -s /etc/nginx/sites-available/firmware.wadamesh.com.conf /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx
2. Cloudflare
- DNS:
A/AAAArecords fortiles,firmware,flasher,@→ the VPS IP, all Proxied (orange cloud). - SSL/TLS: mode Flexible (CF↔origin HTTP) is enough since the origin is
HTTP-only. Do NOT enable "Always Use HTTPS" on
tiles.orfirmware.— the firmware needs plain HTTP there. - Cache Rules:
tiles.wadamesh.com/*→ Eligible for cache, Edge TTL ~14d.firmware.wadamesh.com/releases/*/*.bin→ cache, Edge TTL ~1d.firmware.wadamesh.com/releases/TOUCH(the listing) → short TTL (~60s) or Bypass, so new releases appear promptly.
3. Publishing a release
From a wadamesh checkout (builds both boards, refreshes the listing, rsyncs up):
WADAMESH_VPS=user@your-vps scripts/release.sh beta_2
The on-device check GETs http://firmware.wadamesh.com/releases/TOUCH, finds the
highest beta_<N>, and (once OTA-over-Wi-Fi is re-enabled) pulls
…/releases/TOUCH/beta_<N>/<board>.bin.
Done
- Web flasher ✅ — the guided install page at
wadamesh.com, served fromdeploy/site/and published byscripts/deploy-site.sh(esp-web-tools / Web Serial, per-board install buttons + .bin downloads, manifests generated per release byscripts/build/gen-flasher-meta.pyinto the/latest/and/latest-beta/feeds thatrelease.shrefreshes each publish). flasher.wadamesh.com301-redirects to the apex (seedeploy/nginx/flasher.wadamesh.com.conf) — it is an alias, not its own page.deploy/flasher/is the original standalone flasher page. No deploy script publishes it —deploy-site.shshipsdeploy/site/only — so it is effectively an offline/local copy kept in parity by hand. Retire it or wire it into a deploy target; until then, treatdeploy/site/index.htmlas the only install page users can reach.
TODO before public launch
- Re-enable OTA-over-Wi-Fi in the firmware (currently it version-checks then defers to manual flashing).
- Flip
wadameshrepo public = launch. - Decide tile-proxy sharing: dedicated
tiles.wadamesh.com(this config) vs reusing the meshcomod proxy.
Never commit the VPS IP, SSH keys, or
WADAMESH_VPS. Cloudflare fronts the origin; the deploy target is supplied via the environment at publish time.