Skip to content

Allow USB recovery boot without charging an unsafe battery - #366

Draft
TobiasRoeddiger wants to merge 1 commit into
2.2.10from
codex/usb-no-charge-recovery
Draft

TobiasRoeddiger wants to merge 1 commit into
2.2.10from
codex/usb-no-charge-recovery

Conversation

@TobiasRoeddiger

Copy link
Copy Markdown
Member

A battery rejected by the normal power manager can leave the application waiting before USB starts, making USB diagnosis and reflashing unavailable. Add an automatic USB-only recovery boot to the 2.3.0 FOTA configuration (release branch 2.2.10).

  • Assert the charger CD pin before checked, bounded gauge reads. Keep it high for the whole recovery session if the gauge is unavailable/uninitialized or reports an unsafe battery condition.
  • Start USB mcumgr without normal battery workers, Bluetooth, audio or sensors. Skip the normal DFU indicator callback because those services are not initialized.
  • Power off on USB removal and wake on USB insertion. Healthy USB boots, safe precharging and battery-only boots retain their normal behavior; non-FOTA builds do not enable this feature.
  • Preserve the charger's read-to-clear reset indication by not reading that register during the probe.

Validation: full NCS 3.4.1 FOTA and non-FOTA builds passed. All 12 control-logic tests passed on the host with AddressSanitizer/UndefinedBehaviorSanitizer, including gauge/GPIO failures, threshold boundaries, USB removal and latched inhibition. The tests are also registered in the existing Unity/Twister suite.

Draft pending hardware validation: USB image listing/upload, unplug/replug, CD and battery-current measurements, and operation across the PMIC watchdog interval. No device was flashed. Charge inhibition begins in the application, not before MCUboot; the battery is not physically isolated. This cannot retroactively recover an old firmware that never starts USB. Details and the read-only mcumgr image list command are in docs/usb-battery-recovery.md.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

✅ Unit tests passed

6 passed, 0 failed/error, 0 skipped — view workflow run

Test scenario Platform Result
openearable.unit.sensor_component native_sim/native/64 ✅ passed
openearable.unit.sensor_transport native_sim/native/64 ✅ passed
openearable.unit.usb_recovery native_sim/native/64 ✅ passed
openearable.unit.ring_buffer native_sim/native/64 ✅ passed
openearable.unit.audio_encoder native_sim/native/64 ✅ passed
openearable.unit.audio_startup native_sim/native/64 ✅ passed

Download the unit-test-results artifact for full Twister reports and logs.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Compiler warnings

The extended-warning build completed successfully.

Application compiler warnings

Show warnings
unicast_server/main.cpp:91:33: warning: 'int usb_enable(usb_dc_status_callback)' is deprecated [-Wdeprecated-declarations]
src/Battery/usb_recovery_io.c:99:9: warning: 'usb_disable' is deprecated [-Wdeprecated-declarations]
src/Battery/usb_recovery_io.c:121:9: warning: 'usb_enable' is deprecated [-Wdeprecated-declarations]

View this workflow run

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Build output available:
openearable_v2_firmware.zip
openearable_v2_fota.zip

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

CodeChecker static analysis

✅ No non-style issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant