Files
AutoFilm-ESP32/docs/megaplans/audit/A03-task-wdt.md
gronod 3785f07189
ci / test (push) Successful in 1m6s
ci / firmware (jc4827w543, sdkconfig.s3, esp32s3) (push) Successful in 3m55s
ci / firmware (wroom, sdkconfig.wroom, esp32) (push) Successful in 4m0s
Mark A03 status DONE
2026-09-17 07:58:32 +01:00

3.1 KiB
Raw Permalink Blame History

A03 — explicit task watchdog setup in app_main

STATUS: DONE DEPENDS: A00 (independent of A01/A02 — main/main.c only)

READ: this file, docs/megaplans/AUDIT-MEGAPLAN.md, docs/audit_remediation_plan.md item 4, main/main.c, sdkconfig.defaults

Context (audit correction): the audit's "TWDT never initialized → panic at boot" is unlikely under the current config — sdkconfig.defaults sets CONFIG_ESP_TASK_WDT_EN=y + CONFIG_ESP_TASK_WDT_TIMEOUT_S=10 + CONFIG_ESP_TASK_WDT_CHECK_IDLE_TASK_CPU0=y, and IDF v5.4 auto-initialises the TWDT before app_main, so esp_task_wdt_add(NULL) in the tasks already succeeds. The real gaps: setup is implicit (breaks silently if the Kconfig default ever changes), and every esp_task_wdt_add return value is ignored. Make setup explicit and failures observable. Keep the effective config identical — 10 s already bounds the ~750 ms hal_temp_tick block; do not adopt the audit's 3–5 s suggestion.

IN:

  1. main/main.c, in app_main before the xTaskCreate block, under #if CONFIG_ESP_TASK_WDT_EN:
    esp_task_wdt_config_t wdt_cfg = {
        .timeout_ms = CONFIG_ESP_TASK_WDT_TIMEOUT_S * 1000,
        .idle_core_mask =
    #if CONFIG_ESP_TASK_WDT_CHECK_IDLE_TASK_CPU0
            (1u << 0)
    #else
            0
    #endif
    #if CONFIG_ESP_TASK_WDT_CHECK_IDLE_TASK_CPU1
            | (1u << 1)
    #endif
        ,
    #if CONFIG_ESP_TASK_WDT_PANIC
        .trigger_panic = true,
    #else
        .trigger_panic = false,
    #endif
    };
    esp_err_t wdt_err = esp_task_wdt_init(&wdt_cfg);
    if (wdt_err == ESP_ERR_INVALID_STATE) {
        wdt_err = esp_task_wdt_reconfigure(&wdt_cfg); /* already auto-initialised */
    }
    if (wdt_err != ESP_OK) {
        ESP_LOGW(TAG, "task wdt setup: %s", esp_err_to_name(wdt_err));
    }
    
    Verify field names/signatures against esp_task_wdt.h in the pinned IDF (v5.4) and adjust the sketch only as needed to compile.
  2. In each of input_task, machine_task, ui_task, temp_task: capture esp_err_t werr = esp_task_wdt_add(NULL); and ESP_LOGW(TAG, "... wdt add failed: %s", esp_err_to_name(werr)) on non-OK; continue regardless — the unconditional esp_task_wdt_reset() no-ops harmlessly if the task is not subscribed.

OUT: app_machine, hal_temp internals, UI code, sdkconfig* edits.

FORBIDDEN: disabling the TWDT or idle-task watch; vTaskDelete; shrinking the timeout; committing a generated sdkconfig.

VERIFY:

cmake -S tests/host -B build/host && cmake --build build/host && ctest --test-dir build/host --output-on-failure

(unchanged — main.c is not host-compiled; run anyway to catch regressions). Firmware builds for both esp32 and esp32s3 run in CI on push — confirm both go green.

COMMITS:

  1. Make task watchdog setup explicit in app_main

DoD checkboxes:

  • init-or-reconfigure runs before task creation.
  • esp_task_wdt_add failures are logged in all four tasks.
  • Effective config unchanged: 10 s timeout, CPU0 idle watched, no panic.
  • Both CI firmware builds green.
  • STATUS → DONE here and in the megaplan table.