Add local OLED recovery controls

This commit is contained in:
2026-08-29 19:31:57 +02:00
parent e291e29357
commit 371c0ab896
8 changed files with 605 additions and 49 deletions
+17
View File
@@ -140,6 +140,23 @@ For the OLED-aging policy, leave all three buttons untouched and verify:
`debug display status` may verify an individual transition in a separate timing run. Every display diagnostic counts as activity and holds normal UI rendering for 30 seconds, so do not invoke it between the five- and ten-minute observations of one continuous run. Record a missing, stale, clipped, or implausible status value or incorrect dim/off/wake transition before Phase 7C is marked complete.
### 9. Local controls (Phase 7D)
From a status page, use a short Select press to open **Controls**. Previous/next selects an item; Select activates it. The menu includes serial start/stop, Wi-Fi start/stop/reconnect, HTTPS start/stop, SSH start/stop, writer revocation, display off, and reboot. It must never show or change credentials, Wi-Fi profiles, serial framing, TLS/SSH keys, or I²C scan controls.
Stopping a service, Wi-Fi reconnect, writer revocation, and reboot open a confirmation page. Verify that:
1. Previous/back cancels the confirmation without changing the selected service or writer.
2. A short Select press does not execute the action.
3. Only one continuous two-second Select hold executes the action once; releasing it does not repeat the action.
4. Any simultaneous button chord is ignored and cannot confirm an action.
5. An untouched confirmation expires to the menu after 30 seconds.
6. A dimmed/off OLED consumes the first button press for wake only; its later release and hold must not navigate or confirm an action.
For Wi-Fi lifecycle calls, confirm the immediate result says `Requested`, then use the status pages to observe the asynchronous state change. HTTPS and SSH starts must fail cleanly when neither station nor AP networking is available. Writer revocation must only release the current writer—never assign a replacement—and the UI must never appear as a broker client. For reboot, observe `Restarting...`, then verify all normal boot services and UART0 recovery return.
Run these checks with UART0 available. Repeat appropriate stop/revoke cases with USB CDC, WebSocket, and SSH clients connected; verify the intended session/service is interrupted, unrelated recovery paths remain responsive, and no action injects serial data.
## Configuration A: data and handshake pairs
Connect the following pairs: