Files
ESP32_Serial_Swiss_Army_Knife/docs/web_administration_acceptance.md
T
Commander1024 91267b371e Consolidate Phase 8 documentation
Mark web administration complete, centralize current contracts and
acceptance evidence, and remove superseded slice records. Update
roadmap,
architecture notes, and test references without changing firmware
sources.
2026-09-13 22:27:10 +02:00

5.0 KiB

Web administration acceptance

Phase 8D.22 sign-off — 2026-09-13

The user explicitly accepted the tested firmware: “Yep, I tested the firmware thats a 8d.22 signoff.” Phase 8D is complete for its retained scope. This supersedes earlier per-slice target-pending, parent-review and integration-acceptance gates; it does not require additional testing to establish the user's sign-off. Phase 8A/B/C were already recorded as complete and target-hardware validated in the roadmap, so Phase 8 is complete.

Accepted functionality comprises cookie authentication, isolated browser serial/admin terminals, typed Serial/Accounts/authorized-key/Network/Display/Broker/SSH/HTTPS settings, contextual controls, confirmed generation-safe writer/service/identity actions and retained UART0/native-USB recovery. Current contracts define actual permissions, bounded failures and partial effects; acceptance is not a claim of unrestricted browser-shell parity.

Scope decisions remain effective: 8D.15 dedicated typed network diagnostics was removed (shell diagnostics retained); the unimplemented 8D.19 ordinary browser-session/native-USB control remainder was removed (SSH controls retained). Browser identity Reset/recovery/export was not added. Phase 9 security/production hardening is next only on a separate user request.

Latest firmware evidence

The prior final firmware build passed, reporting 100,556 bytes linked RAM / 1,828,573 bytes flash, at 160 MHz. This is recorded prior build evidence, not a build run during documentation consolidation. Host regression suites and independent implementation reviews were previously reported passing; no new host/runtime test pass is asserted here.

Latest user telemetry, bytes:

Sample / memory capability Free Minimum free Largest block
Boot internal 8-bit 59,808 58,840 31,744
Boot internal DMA 52,052 51,084 31,744
Boot PSRAM 8,196,968 8,183,972 8,126,464
Loaded after burst, internal 8-bit 31,508 2,052 18,432
Loaded after burst, internal DMA 23,752 460 18,432
Loaded after burst, PSRAM 8,136,624 8,065,972 7,995,392

Loaded SSH minimum-free stack was 15,028 bytes. The capture had two active SSH sessions across the serial/admin roles, two serial WebSockets and USB, with SSH holding the serial writer. Browser admin had been used and then closed; it was not active in the captured loaded sample. Web send/queue/protocol error counters were zero; SSH IO errors were zero, with one handshake failure and one session revocation retained without attributing a cause.

Latest broker/serial counters were not supplied, so these transport counters do not establish an exact latest zero-drop or byte-integrity result. No latest full-mix-with-browser-admin-active, individual fault-injection, exact duration, soak, cleanup-cycle or reserve-floor result is inferred. Generic SDK TLS -0x004C / NET_RECV_FAILED is not an OOM diagnosis. Two boot authentication failures could plausibly involve stale browser cookies, but that explanation is unconfirmed.

Earlier acceptance retained without replaying the timeline

  • M1 browser login/logout and M2 shared browser administration were explicitly accepted by the user; later Serial/account/Network presentation and legacy-credential cleanup also received scoped acceptance.
  • The user explicitly accepted the combined binary WebSocket-send fix at 160 MHz, 230400 baud with the full client mix, including browser admin. That prior acceptance stands independently of the latest capture's closed browser-admin socket. It does not imply an unreported latest exact counter comparison or soak duration. Keep the combined send and bounded failed-send isolation, not the earlier frequency-only experiment.
  • Ordinary HTTPS idle cleanup was accepted as working; that is not a guarantee against all future admission failures or owner delays.

Nonblocking follow-ups and evidence limits

The extremely low internal/DMA lifetime minima remain an unresolved transient-headroom follow-up, not a blocker reopening 8D sign-off and not an approved reserve. Capability pools overlap; summed per-region lifetime minima can be conservative/non-simultaneous and do not prove an allocation failure. Do not add internal and DMA numbers together or attribute an error to memory pressure without correlated evidence. HTTPD/dispatcher stack margins, peak correlation, allocation reserve policy and long-run cleanup/soak evidence remain distinct future measurements.

Regression procedures and focused test runners remain available for future changes; listing them is not evidence they all ran on hardware. Documentation-only consolidation changes no firmware, configuration, generated assets or test implementation and performs no build/upload/erase/commit. No new Phase 9 work is authorized by this acceptance.