Skip to content

feat(gui): Read country partitions back after writing them - #111

Merged
miner7222 merged 2 commits into
miner7222:mainfrom
foXaCe:feat/verify-country-write
Sep 27, 2026
Merged

miner7222 merged 2 commits into
miner7222:mainfrom
foXaCe:feat/verify-country-write

Conversation

@foXaCe

@foXaCe foXaCe commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Problem

run_country_change logged {label} patched + flashed and marked the partition done as soon as flash_partition returned Ok. Nothing confirmed the device actually holds the patched country code afterwards.

Change

  • After each successful country-partition flash, the same EDL session dumps the partition again to <work>/<label>.verify.img and compares it byte for byte with the patched image (files_identical, chunked, size-checked first).
  • Match: logs live_country_verified ("{label} read back and verified") and marks the partition flashed, as before.
  • Mismatch (country_reason_verify_mismatch) or read-back error (country_reason_verify_failed): the partition is marked failed with that reason, so run_country_change returns an incomplete-patch error (existing err_country_patch_incomplete path). The standalone Change Country Code operation propagates that failure. The full-flash country phase retains its existing best-effort policy: it warns and continues to slot activation/reset; read-back failure does not fail the entire firmware flash.
  • Only partitions that were written are read back; persist and already-correct partitions are unchanged. Covers both Change Country Code and the full-flash country phase, which share run_country_change.
  • Strings added in all six locales.

The cost is one extra dump of each written country partition (oemowninfo / devinfo / proinfo, which are small).

Testing

  • Scripted-session regression coverage exercises the production write/read-back orchestration: matching bytes, mismatching bytes, dump failure, flash failure (no read attempted), and a missing read-back file. It checks partition/LUN/slot, input/output paths, call order, aggregate success/failure, and whether verified success is logged.
  • Unit test for files_identical: equal files, a single differing last byte past the first chunk, a truncated file, and a missing file (error).
  • cargo test -p ltbox-gui (incl. locale_guards) and cargo clippy -p ltbox-gui --all-targets --features demo pass.
  • Not yet run against a device.

Follow-up validation on Windows: workspace clippy with warnings denied, workspace tests, and cargo deny --locked check pass. The first workspace run hit an unrelated loopback connection reset in download_replaces_destination_atomically; its isolated retry and the full workspace retry passed.

foXaCe and others added 2 commits September 27, 2026 15:12
A country-code write was reported as "patched + flashed" as soon as the
Firehose programmer acknowledged it; nothing checked that the device
now held the patched bytes.

After each successful flash, run_country_change now dumps the partition
again over the same session and compares it byte for byte with the
patched image. A match logs "read back and verified" and counts as
flashed; a mismatch or a failed read-back marks the partition failed
with its reason, so the run reports an incomplete patch instead of
success. Applies to Change Country Code and to the country phase of a
full flash, which share this function. Only partitions actually written
are read back.
Extract the production session boundary and cover successful verification, mismatches, and write/read/file failures. Preserve caller-specific failure policies.

Co-authored-by: GPT-6 Astra <noreply@openai.com>
@miner7222
miner7222 merged commit 2fcf762 into miner7222:main Sep 27, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants