Rollback, and the bug that put it to the test
Wireless updates are only safe if a bad update can't brick a board sitting on someone's wall. So the firmware got rollback.
How it works
New firmware starts on probation. It's kept only after running for a full minute without crashing. If it crashes before then, the board switches back to the previous version, which is still stored in the chip's other update slot. It also remembers the bad version and never installs it again.
The test that failed
To prove it, I published a test build that crashes on purpose. The board crashed, restarted, and crashed again, over and over. Rollback didn't save it.
Two things went wrong. The test build was labeled with the wrong version number inside, so the board thought a newer version was waiting. And while the new firmware was still on probation, it started downloading that "update," into the very slot that held the old firmware. By the time it tried to go back, there was nothing left to go back to.
The fixes
- Firmware on probation never installs updates, so its backup can't be overwritten.
- Every build carries its real version inside, and the admin page reads it when you publish. A mismatch is refused, and test builds need an extra confirmation.
I recovered the board over USB and ran the test again. This time it went back to the previous version on its own. That's exactly why you test the failure case.