From 36d41be422be737c45dafa8afb42d416b51e62b2 Mon Sep 17 00:00:00 2001 From: Commander1024 Date: Tue, 8 Sep 2026 21:40:18 +0200 Subject: [PATCH] Document 8D.12/8D.13 Functional Sign-Off --- docs/agent/code-map.md | 2 +- docs/agent/current-state.md | 2 ++ docs/phase8d12_13_implementation.md | 24 +++++++++++++++++++++++- docs/phase8d_plan.md | 2 ++ 4 files changed, 28 insertions(+), 2 deletions(-) diff --git a/docs/agent/code-map.md b/docs/agent/code-map.md index 8502aa6..50e965a 100644 --- a/docs/agent/code-map.md +++ b/docs/agent/code-map.md @@ -58,7 +58,7 @@ This is a semantic map, not a complete file inventory. Start here, then read the ## Web and WebSocket serial -- **Current 8D.12/8D.13:** `web_network_settings.{c,h}` owns optional admin-only GET `/api/settings/network` and GET/POST `/api/settings/network-operation`; `web_ui.c` supplies Network, UTF-8/hex SSID editing and explicit transient-secret/connection controls. `wifi_manager` owns generation-checked secret-free snapshots/patch/save/stored-only load and radio transitions; `mdns_service` owns independent conditional hostname persistence, with manager reannouncement. Existing dispatcher receives IDs only. 768-byte request/2,048-byte snapshot/128-byte result, one slot/one-second timer with 30-second queued expiry plus scheduling latency; no hard cancellation. 27 handlers/six sockets, no task/stack/queue/schema growth. Backend/cookie PASS, UI agent 97+renderer/CSP and review PASS, lifecycle agent21 PASS; final parent build/tests and target/resource validation pending. Full contract/exclusions/checklist: `docs/phase8d12_13_implementation.md`. Both phases user-authorized together; no 8D.14/M3/sign-off claim. Older next-phase statements below are historical. +- **Current 8D.12/8D.13 — user functional sign-off 2026-09-08, including Settings presentation:** `web_network_settings.{c,h}` owns optional admin-only GET `/api/settings/network` and GET/POST `/api/settings/network-operation`; `web_ui.c` supplies Network, UTF-8/hex SSID editing and explicit transient-secret/connection controls. `wifi_manager` owns generation-checked secret-free snapshots/patch/save/stored-only load and radio transitions; `mdns_service` owns independent conditional hostname persistence, with manager reannouncement. Existing dispatcher receives IDs only. 768-byte request/2,048-byte snapshot/128-byte result, one slot/one-second timer with 30-second queued expiry plus scheduling latency; no hard cancellation. 27 handlers/six sockets, no task/stack/queue/schema growth. Parent integrated tests/build PASS; latest styling UI100 + renderer/CSP/Chromium checks, 99,548 B RAM / 1,744,325 B flash. User full-mix evidence accepted; loaded internal/DMA minima2,276/156 B remain resource follow-ups, not reserve approval. Full contract/exclusions/checklist: `docs/phase8d12_13_implementation.md`. Both phases user-authorized together; no 8D.14/M3 claim. Older next-phase statements below are historical. - **8D.11:** `web_account_settings.{c,h}` extends Accounts with fingerprint-only POST `/api/settings/accounts/keys` and key-add/key-delete/key-clear on the existing operation endpoint/dispatcher. `user_database.{c,h}` owns zero-wait target-checked snapshots and canonical conditional key mutations. `web_ui.c` handles confirmations, sparse stable indices and self-revocation uncertainty. 24 handlers, six sockets; no new task/stack/queue depth. Host-tested/build-verified, target pending. Contracts/tests/checklist: `docs/phase8d11_implementation.md`. diff --git a/docs/agent/current-state.md b/docs/agent/current-state.md index fc7c81f..e78e6dc 100644 --- a/docs/agent/current-state.md +++ b/docs/agent/current-state.md @@ -4,6 +4,8 @@ This file is working memory. Update it during active work and before handoff; do ## Development state +- **8D.12/8D.13 + Settings presentation functionally signed off (2026-09-08):** User explicitly accepts after 60-second boot/full-mix telemetry. Web writer8, web17/SSH10/USB11 observers, both admins, two cookies at230400 8N1 RTS/CTS DTR active. Web send/queue/protocol/close-failure0, SSH handshake/auth/IO failures0; retain SSH rejected1 byte, web rejected1 frame/1 byte, serial connect3/disconnect1, cookie login3/logout1, authfailures2 boot/3 loaded without causal diagnosis. Loaded free internal/DMA/PSRAM31,512/23,756/8,112,140 B; minima2,276/156/8,070,736 B; largest20,480/20,480/7,995,392 B. SSH stack min18,468 boot/16,276 loaded. Exact samples/counters/limits: `docs/phase8d12_13_implementation.md`. Supersedes target-pending/no-signoff wording below for implemented phases and visual refinements. Very low lifetime internal/DMA minima remain transient-headroom follow-up (conservative non-simultaneous region sums, not proof allocation failed); HTTPD/dispatcher floors/peak correlation and numeric reserves unapproved, not reopening functional acceptance. No invented individual checklist/soak/full-M3 pass, no 8D.14 authorization. Documentation only, no source/config/build/test/device/assets/commit action. + - **Settings presentation unified (2026-09-08), user-requested visual refinement:** Accounts/Network now use Serial-style 600px label/value definition lists, shared form styling, compact muted help, consistent Refresh/result labels and action grouping. Public-key textarea/generated-password fields styled; checkboxes intrinsic-width. Safe DOM text replaces preformatted summaries; readable ASCII SSID/hex fallback retained, pre-wrap preserves significant spaces (review finding fixed with rendered-width regression). IDs/events/auth/mutations/secret cleanup/terminal ownership unchanged; no backend/assets changes. Parent UI100 behavior groups plus HTML/renderer/CSP and headless Chromium geometry/whitespace checks at320/600/1200px PASS; pio run PASS23.69s, 99,548 B RAM / 1,744,325 B flash (+0/+1,744 vs preceding ASCII-summary build). Diff check PASS. Fixtures/browser layout checks are not target visual sign-off or live Wi-Fi validation. No upload/erase/commit. - **8D.12/8D.13 implemented together by user authorization (2026-09-08); host-tested/build-verified, target pending:** Backend and admin Network UI deliver 8D.12 nonsecret STA/AP/profile/mDNS edits and explicit persistence, then 8D.13 secret replacement/disabled-STA clear and connection controls. Exact API, byte SSID/UTF-8+hex UI, owner/generation/persistence/uncertainty contracts: `docs/phase8d12_13_implementation.md`. One 768-byte request, 2,048-byte snapshot, 128-byte result; one login-bound slot and one-second ESP timer, 30-second non-executing expiry plus scheduling latency, not hard cancellation. Existing dispatcher IDs/manager owner; accepted != online. Wi-Fi Load stored-only, no reset/default-secret/export; mDNS separate generation/Set/Save/Load/Defaults/reannouncement. 27 handlers/six sockets, no stack/task/queue/schema growth; staged optional route failures preserve unrelated routes. Reported backend/cookie Network PASS; backend P3 queue-drop-counter fix complete; UI agent97+renderer/CSP/review PASS; lifecycle agent21 PASS. Parent final reruns PASS Network five production-path groups, cookie Network five+shared/accounts/serial-settings/admin, console boundary/canonical accounts, lifecycle21, UI97+CSP, idle18+guards, transport25/tickets12, store--serial, diagnostics12+guard and diff check. Independent reviews no remaining actionable findings. Parent pio run PASS24.99s, 99,548 B RAM / 1,742,437 B flash (+288/+36,656 vs accepted legacy cleanup). Earlier pre-final-UI integration build emitted nonfatal FATFS_PRINT_FLOAT config warning; no unrelated config edits. Host owner paths use radio/scheduler/storage doubles, not real network validation. Timer heap, memory floors, HTTPD/dispatcher margins, live Wi-Fi/mDNS/DNS/trust and target checklist remain pending. Profile editor is not explicit-index connection selection: only canonical Next profile. UART0/USB recovery, danger confirmations, no same-response delivery guarantee and unchanged browser-shell restrictions documented. No 8D.14, full M3, target acceptance or reserve approval. Documentation agent touched only authorized docs, no source/tests/assets/build/device/commands; also corrected stale SSH-to-HTTPS startup dependency against `main.c` from accepted legacy cleanup. Older wait-for-8D.12 statements below are superseded, not earlier scoped sign-offs. diff --git a/docs/phase8d12_13_implementation.md b/docs/phase8d12_13_implementation.md index e7aed76..a8f0a11 100644 --- a/docs/phase8d12_13_implementation.md +++ b/docs/phase8d12_13_implementation.md @@ -2,10 +2,32 @@ ## Status and scope (2026-09-08) -The user authorized both phases together. Backend and admin-only Settings/Network UI are implemented: **8D.12** delivers secret-free STA/AP/profile projections, non-secret edits, explicit persistence and mDNS; **8D.13** adds explicit Wi-Fi password replacement/disabled-STA clear and manager-owned connection controls. This supersedes older wait-for-8D.12 statements, not previous scoped acceptance. No 8D.14 work, M3 completion, target sign-off or numeric memory reserve approval is claimed. +The user authorized both phases together. Backend and admin-only Settings/Network UI are implemented: **8D.12** delivers secret-free STA/AP/profile projections, non-secret edits, explicit persistence and mDNS; **8D.13** adds explicit Wi-Fi password replacement/disabled-STA clear and manager-owned connection controls. This supersedes older wait-for-8D.12 statements, not previous scoped acceptance. **User functional sign-off received on 2026-09-08**, including the subsequent Settings presentation refinements. No 8D.14 work, M3 completion or numeric memory reserve approval is claimed. Source authority: `src/web_network_settings.{c,h}`, `wifi_manager.{c,h}`, `wifi_config.{c,h}`, `mdns_service.{c,h}`, `mdns_config.{c,h}`, `admin_ssh_console.{c,h}`, integration in `web_server.c`/`src/CMakeLists.txt`, and authored `web_ui.c`. Contract/test details: `tests/web_network_settings/README.md`, `tests/web_ui_session/network.cjs`, cookie Network tests and server lifecycle tests. This documentation handoff changes no source, tests, generated assets or commands. Browser-shell Wi-Fi/mDNS restrictions are unchanged; typed routes do not grant general command execution. +## Functional acceptance and target telemetry — 2026-09-08 + +User supplies 60-second fresh-boot and full-client-mix samples and explicitly states: “So that's a functional sign-off from me.” Accept implemented 8D.12/8D.13 and their readable-SSID/consistent Settings presentation refinements. This supersedes earlier target-pending/no-signoff statements, not historical host evidence or limits. No individual unreported mutation/persistence/recovery/fault-injection test, soak duration, all-key test, exact flashed revision, browser version or numeric resource-reserve approval is inferred. No next-phase implementation is authorized by sign-off alone. + +| Memory (bytes) | Boot free / minimum / largest | Full mix free / minimum / largest | +|---|---|---| +| Internal 8-bit | 66,000 / 60,632 / 31,744 | 31,512 / 2,276 / 20,480 | +| Internal DMA | 58,244 / 52,876 / 31,744 | 23,756 / 156 / 20,480 | +| PSRAM | 8,246,156 / 8,184,100 / 8,126,464 | 8,112,140 / 8,070,736 / 7,995,392 | + +Minima are conservative sums of individual-region lifetime minima, not necessarily simultaneous; internal/DMA capabilities overlap. Loaded settled internal/DMA free is only 308 bytes below the preceding cleanup sample (31,820/24,064), while minima fell from 15,740/7,984 to 2,276/156. This is a significant transient-headroom concern, not proof of an allocation failure or attribution to styling/Network changes. Different admission/operation histories are unmeasured. Functional acceptance does not approve these reserves. HTTPD/dispatcher stack margins and peak-allocation correlation remain follow-ups; SSH's 20,480-byte owner stack has minimum-free 18,468 boot / 16,276 loaded bytes. + +Boot: SSH/HTTPS each starts once without startup failure, no SSH sessions or broker clients, UART stopped, USB attached/host closed. Five accounts/two admins; mDNS announced as sak-1024.local with ESP_OK. Two web requests/auth failures already present; zero cookie login attempts, invalid credentials or sessions. Prior user explanation was stale pre-flash browser sessions; this run's requests are not separately traced. + +Loaded: web client8 sole writer, web17/SSH10/USB11 observers; SSH admin and browser admin active, two cookie sessions. SSH user/admin authenticated by public key; browser user/admin by password. UART running 230400 8N1 RTS/CTS, DTR active, threshold96; sampled UART RX/TX and all broker pending/events zero. mDNS/SSH/HTTPS operational/ESP_OK. No broker drop-counter output supplied; empty pending queues do not establish lossless traffic. + +SSH counters: TCP/handshake success/auth attempts 2/2/2; handshake/auth/timeout/capacity/request rejection/IO/session-revocation failures zero. Broker connect1/no failures/disconnect, writer request1/grants0/denial1/revocations0; admin admission1/no failures/backpressure. Stream RX81/accepted80/rejected1, TX216,828 bytes. Retain the rejected byte; observer/lease enforcement is a possible explanation, not a confirmed diagnosis. + +Web admin counters: tickets issued/consumed1/1, all rejection/capacity0, connected1/disconnected0; RX7/TX481 bytes, protocol/backpressure/send/queue failures0. Web lifecycle starts1/failures0/stops0; requests283/authenticated280/auth failures3, root3/status270/tickets3/assets3, response errors0. Serial tickets issued/consumed3/3, rejected/expired0; serial WS connect3/disconnect1, admission/service/broker failures0. RX frames15 accepted/1 rejected, bytes19 accepted/1 rejected; TX716 binary frames/307,154 bytes, control12 frames/997 bytes. Writer requests3/grants1/denials2, releases/revocations0. Send/queue/protocol/close-failure counters0. Cookie login attempts3, invalid credentials/throttled/capacity/CSRF0, logouts1. A logout/relogin is consistent with the serial disconnect/reconnect and extra auth failure, but their causal relationship is not established by aggregate counters. This is not an all-zero-rejection or no-disconnect run. + +This evidence/sign-off update is documentation only: no source/config/build/test/device/asset/commit actions. Resource follow-ups remain recorded without reopening functional acceptance. + ## Presentation refinement — 2026-09-08 On user request, Accounts and Network adopt Serial's compact label/value grids, form styles, help typography and action spacing. Account/key/Network summaries are semantic definition lists populated with DOM text; all information remains available. Printable ASCII SSIDs remain quoted, other bytes use hex, and value cells preserve significant spaces while wrapping. Key textarea, generated-password field and checkboxes share form styling. IDs, request/operation behavior, warnings, secret clearing and terminal/lease ownership are unchanged. diff --git a/docs/phase8d_plan.md b/docs/phase8d_plan.md index 3a8701c..bbeb207 100644 --- a/docs/phase8d_plan.md +++ b/docs/phase8d_plan.md @@ -1,5 +1,7 @@ # Phase 8D — Incremental web administration plan +**Latest functional acceptance (2026-09-08):** User signs off implemented **8D.12/8D.13 and Settings presentation refinements** after boot/full-client-mix telemetry. Supersedes target-pending/no-signoff statements for this scope below, not historical build/test evidence or unreported checklist limits. [Acceptance record](phase8d12_13_implementation.md) retains all samples and counters: web sole writer + web/SSH/USB observers, both admins; no web send/queue/protocol failures or SSH handshake/auth/IO failures, but rejected input and one logout/disconnect retained without diagnosis. Loaded internal/DMA free31,512/23,756 B, minima2,276/156 B, largest20,480 B. Low conservative lifetime minima remain a resource follow-up, not approved reserves or proof of allocation failure. No full M3 claim or next-phase implementation authorization; 8D.14 awaits a separate request. + **Current implementation (2026-09-08):** User authorized **8D.12 and 8D.13 together**, backend and Network UI delivered. 8D.12 covers nonsecret STA/AP/profile/mDNS edits and persistence; 8D.13 adds explicit secret replacement/disabled-STA clear and connection controls. Profile selection means selecting a configuration to edit; connection control is canonical **Next profile**, not explicit-index selection. 27 handlers/six sockets, one bounded slot/timer, no task/stack/queue/schema growth. Backend/cookie Network PASS, UI agent97+renderer/CSP/review PASS, lifecycle agent21 PASS; backend P3 queue-drop-counter finding fixed. **Parent integrated suites and build PASS:** 24.99 s, 99,548 B RAM / 1,742,437 B flash (+288/+36,656 vs legacy-cleanup baseline). Parent UI97/CSP, lifecycle21, Network/HTTP policy, canonical console/accounts, transport/tickets, idle/store/diagnostics checks passed; exact attribution below. **Target behavior, timer heap/memory floors and HTTPD/dispatcher stack margins remain pending.** [8D.12/8D.13 implementation](phase8d12_13_implementation.md) is the exact API/SSID/secret/uncertainty contract and checklist. No Wi-Fi reset/default-secret/export, browser-shell policy widening, 8D.14 work, M3 completion or target sign-off. Supersedes historical next-request restrictions below; previous scoped acceptance stands. **8D.11 implementation history (2026-09-08):** User-requested **8D.11 implemented, host-tested/build-verified; target sign-off pending**. Accounts fingerprint listing and Ed25519/P256 import/delete/clear use canonical target-checked APIs and the existing dispatcher. Sparse-slot selection regression fixed; 24 handlers/six sockets, no new task/stack-size/queue expansion. Final build 96,076 B RAM / 1,703,685 B flash. [8D.11 record](phase8d11_implementation.md) contains API/bounds, test attribution and pending hardware checklist. Supersedes historical wait-for-8D.11 instructions below; 8D.8–8D.10/M2 remain accepted. No M3 completion or 8D.12 work.