feat(gui): Read country partitions back after writing them - #111
Merged
Merged
Conversation
A country-code write was reported as "patched + flashed" as soon as the Firehose programmer acknowledged it; nothing checked that the device now held the patched bytes. After each successful flash, run_country_change now dumps the partition again over the same session and compares it byte for byte with the patched image. A match logs "read back and verified" and counts as flashed; a mismatch or a failed read-back marks the partition failed with its reason, so the run reports an incomplete patch instead of success. Applies to Change Country Code and to the country phase of a full flash, which share this function. Only partitions actually written are read back.
Extract the production session boundary and cover successful verification, mismatches, and write/read/file failures. Preserve caller-specific failure policies. Co-authored-by: GPT-6 Astra <noreply@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
run_country_changelogged{label} patched + flashedand marked the partition done as soon asflash_partitionreturnedOk. Nothing confirmed the device actually holds the patched country code afterwards.Change
<work>/<label>.verify.imgand compares it byte for byte with the patched image (files_identical, chunked, size-checked first).live_country_verified("{label} read back and verified") and marks the partition flashed, as before.country_reason_verify_mismatch) or read-back error (country_reason_verify_failed): the partition is marked failed with that reason, sorun_country_changereturns an incomplete-patch error (existingerr_country_patch_incompletepath). The standalone Change Country Code operation propagates that failure. The full-flash country phase retains its existing best-effort policy: it warns and continues to slot activation/reset; read-back failure does not fail the entire firmware flash.persistand already-correct partitions are unchanged. Covers both Change Country Code and the full-flash country phase, which sharerun_country_change.The cost is one extra dump of each written country partition (
oemowninfo/devinfo/proinfo, which are small).Testing
files_identical: equal files, a single differing last byte past the first chunk, a truncated file, and a missing file (error).cargo test -p ltbox-gui(incl.locale_guards) andcargo clippy -p ltbox-gui --all-targets --features demopass.Follow-up validation on Windows: workspace clippy with warnings denied, workspace tests, and
cargo deny --locked checkpass. The first workspace run hit an unrelated loopback connection reset indownload_replaces_destination_atomically; its isolated retry and the full workspace retry passed.