If Bluefruit.begin fails, BLE OTA mode won't actually start and the board might require a reboot to reattempt.
Fixes:
- Bluefruit.begin returns false in NRF52Board.startOTAUpdate if OTA mode fails to start. User is notified of the fault through existing error message in CommonCLI and can reattempt "start ota" command.
The text preview was the last part of the keyboard still working in bytes
rather than codepoints. cpl is how many characters physically fit on a
line, so dividing byte offsets by it counted every 2-byte Cyrillic/Greek/
accented character as two: lines held half the text they had room for, and
a break could land inside a codepoint. Both display drivers are
permanently single-font, so translateUTF8ToBlocks() passes UTF-8 straight
through -- the truncated sequence reached print() and drew as garbage on
both sides of the break. Line boundaries now walk the buffer with the same
kbUtf8*() helpers insertion/backspace/T9 already use, and the per-line
buffers are sized for a full line of 2-byte characters.
Caps-lock also gets an underline on the shift key: it sets caps too, so
the highlight alone made a one-shot Shift and a held lock indistinguishable
despite capitalising one letter vs. every following one.
Drops UITask::applyFont() -- setSingleFont() is a no-op on both drivers
since they were pinned to misc-fixed, so it did nothing, and use_lemon_font
has had no Settings row for a while. The pref itself stays: it's part of
the on-disk layout. Retires the matching stale rationale on scriptHint().
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Compact mode (Settings > Keyboard's "Ext. KB" row) is meant to guarantee
operation with no joystick at all, but it was still half-tied to the
on-screen grid it hides:
- arrows now move the text cursor directly instead of a grid selection
nobody can see, and Tab opens the placeholder picker directly instead of
the row/col-dependent Hold-Enter dispatch
- plain Enter submits the field (there's no grid cell to have deliberately
landed on), same as Fn+Enter
- Fn+letter's accent popup no longer gates on the grid's script/T9
settings -- CardKB always types plain Latin regardless of them, so the
gate only made the gesture silently stop working
- the whole status line is gone: nothing it showed (script, T9-vs-ABC,
caps) is actionable from an external keyboard. The freed height goes to
message-preview lines, floored at the smallest grid's footprint so
cursor mode's own hint block still fits
- the accent popup gets a fixed slot instead of anchoring on a `row` that
is never deliberately navigated to in this mode
Also fixes a text-corrupting invariant break: moveCursorDirect() and
openPlaceholders() move the cursor without finalizing a pending T9
multi-tap cycle, so a later tap on the same cell within the timeout
overwrote an unrelated character. Every other cursor-moving path already
cleared it.
Fn+Tab is dropped as a separate shortcut -- plain Tab already covered
every case it did. Fn+Enter no longer reads as a dead key in cursor mode.
Direct typing moves into insertTyped(), one translation point documenting
what a future relabelled-keycap layout (Cyrillic/Greek) would need.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- DM/room unread badges could claim messages the ring no longer held
(same class as the channel fix in 6470afaf, not covered by it):
getDMUnread()/getDMUnreadTotal() now clamp to dmHistCountForContact(),
and a new reconcileDMUnread() (called once per loop()) frees any
_dm_unread_table slot whose ring occupancy has dropped to 0, so a
17th sender isn't starved by stale entries. onContactRemoved() now
also clears _dm_unread_table -- the one per-contact table it was
missing.
- Shift didn't capitalise ł/ń/ź/ż (+ĺ/ľ/ň/ž): the Latin Extended-A
case-pairing rule assumed a single parity for the whole block, but it
flips around the unpaired codepoints ĸ/ʼn/Ÿ. Fixed with four
sub-ranges, verified exhaustively over U+0100-U+017F.
- Triple-click could still toggle the buzzer while locked on
PIN_USER_BTN/PIN_USER_BTN_ANA boards (joystick path already guarded
this).
- millis() wraparound: 4 absolute comparisons in UITask.cpp (battery
poll, auto-off, lock-wake, backlight) converted to the existing
(int32_t)(millis()-deadline)>=0 idiom; MyMeshBot.h's DM-throttle
eviction now picks the oldest slot by elapsed time instead of raw
t_ms, which picked the wrong slot right after a rollover.
- Long-press bypassed checkDisplayOn() on all 5 call sites -- neither
woke the display nor extended auto-off, and could deliver
KEY_CONTEXT_MENU to the invisible screen. Moved the gate inside
handleLongPress() itself instead of patching each site.
- CardKB's backspace/printable-insert branches didn't reset t9_cell,
so typing right after a T9 cycle tap could get silently overwritten
by a same-cell re-tap within the T9 timeout.
- buildContactList()'s counts[MAX_CONTACTS] was a 1400 B int array on
the 4 KB loop() stack; values are bounded by DM_HIST_MAX (32), so
now uint8_t.
- ACK table treated ack==0 as a wildcard: isAckPending(0) matched any
free slot, and processAck() with an all-zero ACK matched the first
free slot and returned its stale contact pointer. Both now skip/reject
ack==0, and the matched slot's contact pointer is cleared alongside
its ack hash.
- ensurePageOrderInit() could write one byte past page_order[13] when
migrating a saved order with all 13 slots full and CLOCK last --
guarded on insert_at < PAGE_ORDER_LEN.
Two findings from the same review were resolved as no-op decisions,
not code changes: !buzz over DM ignoring quiet hours is intentional
(the pull exemption is meant to cover the buzzer), and the offline
queue's full-queue drop-newest behaviour is upstream code, left alone.
Build-verified green on WioTrackerL1_companion_solo_dual (RAM 71.1%,
Flash 66.6%) and WioTrackerL1Eink_companion_solo_dual (RAM 73.0%,
Flash 67.9%).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The per-channel unread counter was independent of the ring's actual
contents, so the two drifted apart:
- Opening a channel whose entries had been evicted left the badge
claiming messages the list could no longer show. The viewing-session
bookkeeping computes the count from an _unread_at_entry snapshot, and
with an empty list _hist_visible is 0, so entering only knocked the
count down by one instead of clearing it (badge "7", empty list, then
"6").
- Eviction from a full ring decremented the counter for any dropped
entry, including already-read ones, undercounting the newer unread
messages the counter actually refers to.
chUnread()/getTotalChannelUnread() now clamp to the channel's ring
occupancy, so the badge can never promise more than the history holds
whatever the raw counter says, and eviction only decrements when the
entry being dropped was itself unread.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
mkdocs will only consider the first H1 (if any) and subheaders under it for the table of contents
this increases the header levels of everything below "important concepts" by 1 so that the table of contents correctly resolves them
Post-review cleanups, no behaviour change:
- botScanCommands() parsed the command name and its two args with three
near-identical read-token loops; extracted a single readToken() lambda.
- Fn+Esc lock branch turned the display on twice (the unlock arm repeated
what the branch head already did); dropped the redundant call.
- setGpioMode()'s comment said "Cycle" (cycling lives in GpioScreen); now
describes what it actually does — set a specific mode + persist.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Bot Actions (!buzz/!gps/!advert/!gpio1-4) ran their side effect
immediately during botScanCommands(), before quiet-hours/cooldown/
per-contact throttle were checked -- those gates only suppressed the
reply text, not the actual buzz/GPS toggle/advert/pin write. botCommandReply()
now only records what was requested; applyPendingBotActions() runs the
deferred effects once a wrapper's throttle checks pass and the ack sent,
mirroring the existing _locfix_requested pattern. resetPendingBotActions()
clears everything on every throttled/aborted path.
- CardKB's Fn+<letter> accent-popup shortcut bypassed the locked-input gate
(it called into KeyboardWidget directly instead of through the
enqueueKey()/dequeue path every other key uses, so it wasn't discarded
while _locked). Now checks _locked itself.
- Since a locked device now correctly ignores CardKB entirely, Fn+Esc
(single press) is added as CardKB's own lock/unlock gesture -- otherwise
a CardKB-only setup had no way to unlock. Esc rather than the adjacent
Fn+Backspace, to avoid an accidental press.
- botScanCommands() now parses up to two arguments per command instead of
one. Used by "!gps fix [seconds]" to override the default 90s timeout
(clamped 15-300s) for a poor sky view where 90s isn't always enough to
reach isLocFixReady()'s HDOP/satellite bar.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Satellite count alone is a poor proxy for fix quality -- few satellites
in good geometry can beat many in poor geometry. LocationProvider now
exposes getHDOP() (default -1 = unsupported); MicroNMEA implements it.
isLocFixReady() prefers HDOP <= 2.0 when available, falling back to the
old >=8 satellite threshold for providers that don't report it (e.g.
RAK12500/u-blox).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Same fix as hotfix/admin-login-timeout (96b44460). AdminScreen's only
guard was "_phase == LOGIN" (true for any node sat at the login
screen), not that the reply actually named _target. Now also checks
pub_key against _target.id.pub_key.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
AdminScreen::onRoomLoginResult()'s only guard was "_phase == LOGIN" --
true for *any* node currently sat at the login screen, not specifically
_target. Combined with UITask::onRoomLoginResult()'s current-screen
dispatch (not requester-based), a slow reply for an earlier login
attempt (this screen's own previous target, or even MessagesScreen's)
arriving while the user has since opened Admin on a different,
password-less node -- still parked at the blank LOGIN keyboard, so
_phase == LOGIN here too -- was accepted as that new node's own login
result, flipping _admin_ok/_phase to COMMAND without ever actually
authenticating with it.
Root-caused by cancelUiPendingLogin() (previous commit): that fix
covers the "gave up, then it resolved late" path, but not "a reply for
a genuinely different pubkey arrives while merely _phase == LOGIN".
Checking pub_key against _target.id.pub_key closes that regardless of
which path let the reply through.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Same fix as hotfix/admin-login-timeout (5a5ebe9f). UITask::onRoomLoginResult()
dispatches by whichever screen is currently shown, not by who sent the
request, so a reply arriving after AdminScreen gave up (Cancel or the
timeout fix) could land on MessagesScreen instead and persist its own
unrelated _login_pw as the "confirmed" password for that pubkey.
MyMesh::cancelUiPendingLogin(pub_key) stops tracking the request on
give-up so a late reply matches nothing instead.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
UITask::onRoomLoginResult() dispatches a login reply to whichever
screen is *currently* shown (curr == admin_screen ? AdminScreen :
MessagesScreen), not to whoever actually sent the request. Neither
giving up path (manual Cancel, or the timeout added in 23f43cac) told
MyMesh to stop tracking the request, so a reply that still arrived
after the user had navigated away landed on whatever screen they'd
moved to instead -- most likely MessagesScreen, which then persisted
its own unrelated _login_pw as the "confirmed" password for that
pubkey, silently corrupting the saved password even on a genuine
success.
Adds MyMesh::cancelUiPendingLogin(pub_key), pubkey-guarded so it's a
no-op if a newer request has since overwritten ui_pending_login, called
from both of AdminScreen's give-up paths. A late reply now simply
matches nothing and is dropped.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Same fix as hotfix/admin-login-timeout (05609019). Tools > Admin >
System > "Admin password" changes the remote's admin credential but
never updated this device's saved copy, so the next login retried the
password just replaced -- likely the actual trigger behind the
"stuck on Logging in..." report. Parses CommonCLI's "password now: <v>"
success echo and saves that as the new on-device password.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Tools > Admin > System > "Admin password" (set-only, sends "password
<new>") changes the remote node's own admin credential, but nothing
updated this device's saved copy of it -- so the very next login
attempt to that node retried the password just replaced, landing
straight in the "stuck on Logging in..." case fixed in the previous
commit. Likely the actual trigger behind that report.
CommonCLI::handleCommand() always echoes a successful password change
back as "password now: <value>" (truncation and all), so parsing that
reply gives the exact value now required to log back in, rather than
trusting what we sent (which the remote may have truncated further).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Turns GPS on (if it wasn't already), waits for a stabilised fix
(isValid() + >=8 satellites, then averages 10s of readings), sends the
position, and restores GPS to whatever state it was in before -- up to
a 90s timeout, after which it reports a partial fix (if it got any
samples) or plain failure.
Replies in two parts since a fix takes seconds-to-minutes, unlike every
other bot command here: an immediate "acquiring fix..." ack (through
the existing synchronous command path), then the actual position as a
separate follow-up message once ready, delivered to whichever
destination (DM/room/channel) the request came from. Only one fix can
be in flight at a time -- a second request while one is pending gets an
immediate "already pending" instead of silently replacing it.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
AdminScreen's LOGIN phase had no timeout, unlike its COMMAND phase
(_cmd_deadline_ms). If a login reply never arrived -- most commonly a
saved password gone stale after the remote node's password changed,
silently dropped instead of nacked -- the screen stayed stuck with only
a manual Cancel to escape.
sendRoomLogin() now returns the same est_timeout sendAdminCommand()
already exposes; AdminScreen uses it to arm a deadline (poll(),
mirroring the COMMAND-phase pattern) that forgets the stale password
and returns to the picker on expiry, same as an explicit login
rejection already does.
Same fix as hotfix/admin-login-timeout (23f43cac), split out of this
branch's other in-progress work.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
AdminScreen's LOGIN phase had no timeout, unlike its COMMAND phase
(_cmd_deadline_ms). If a login reply never arrived -- most commonly a
saved password gone stale after the remote node's password changed,
silently dropped instead of nacked -- the screen stayed stuck with only
a manual Cancel to escape.
sendRoomLogin() now returns the same est_timeout sendAdminCommand()
already exposes; AdminScreen uses it to arm a deadline (poll(),
mirroring the COMMAND-phase pattern) that forgets the stale password
and returns to the picker on expiry, same as an explicit login
rejection already does.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Add Settings > Keyboard "Ext. KB" row (boards with a CardKB-capable I2C
bus only): switching it to Compact hides the letter grid and special-row
icons in favour of a one-line status (script/page, caps) plus a Fn-shortcut
reminder, since an external-keyboard typist never looks at the on-screen
grid. Accent/placeholder popups still render as before. Off by default.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Select nodes had this flag enabled, testing by the community
and hardware specs indicate this can be enabled global for all
node types using this chipset.
Any nodes down the line that may be quirky can be individually
disabled with `-U USE_CC310_HW_CRYPTO`.
CardKB is level-triggered (repeats the held byte every poll) and its Enter
key collided with the on-screen keyboard grid's own commit action, causing
duplicate characters and accidental message sends. Debounce polling and use
the CardKB v1.1 Fn modifier (confirmed working on real hardware) instead of
tracking navigation state: plain Enter now behaves like the physical centre
button, Fn+Enter submits, Fn+Tab opens the Hold-Enter equivalent, and
Fn+<letter> opens that letter's accent popup directly.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>