Commit Graph
27242 Commits
Author SHA1 Message Date
J. Nick Koston 79f27d7a19 Merge branch 'drop-redundant-app-state-or' into integration 2026-04-11 16:39:14 -10:00
J. Nick Koston 515ec544ce [tests] Extract STATUS_LED_SETTLE_S constant, fix idle count check
Extract the 0.3s magic sleep into a named constant explaining why that
duration is chosen (feed_wdt re-dispatches every ~3 ms; 300 ms gives
~100 opportunities). Fix the idle-write check to snapshot AFTER the
clear instead of before it, so writes still in-flight from the error
phase don't inflate the delta.
2026-04-11 16:32:15 -10:00
J. Nick Koston 542b1fc7f3 [tests] Add set→clear→re-set round-trip check for status_led
Verifies that after clearing all status flags, re-setting a flag makes
status_led_light resume writing to its output. Guards against a future
idle optimization (like #15642) where status_led disables its own
loop() when idle: if the re-enable path were broken, the second set
would not produce writes.

Also checks that writes STOP after all flags are cleared (counter
should not keep growing), proving status_led_light correctly stops
blinking in steady state.
2026-04-11 16:28:54 -10:00
J. Nick Koston 1b1adb841a [core] Fix clang-format: remove extra blank line 2026-04-11 16:21:43 -10:00
J. Nick Koston 424f1c7b0a [core] Rename any_component_has_status_flag and add integration tests
Drop the trailing underscore from any_component_has_status_flag now
that the method is public. Trailing underscores in the codebase are
reserved for protected/private members per clang-tidy naming rules,
which caused a CI failure on the previously-named public helper.

Add integration tests covering:
- Single-component status_set/clear for warning and error
- Multi-component OR semantics (both clear orders)
- Warning and error independence
- End-to-end proof that status_led_light::loop() reads App.app_state_
  and writes its output when the bits are set (via a fake template
  output whose write_action bumps a counter exposed as a sensor)
2026-04-11 16:20:05 -10:00
J. Nick Koston d9c6b27cf2 [core] Drop per-iteration app_state_ accumulation from main loop
Application::loop() used to, on every iteration of the inner component
loop, OR each component's state into a local accumulator and then OR
that into this->app_state_, finally overwriting this->app_state_ with
the accumulator after the loop. That was ~5 instructions per component
per loop iteration on the hot path, paying to rebuild state that's
already kept current elsewhere.

STATUS_LED_WARNING / STATUS_LED_ERROR are the only app_state_ bits
anything reads. Component::set_status_flag_() already writes them to
App.app_state_ directly the moment they're set, so any reader (status_led
components, feed_wdt's LED re-dispatch) already sees them without the
per-iter OR. The per-iter OR only ever re-set bits that were already
there — pure dead code on the hot path.

The clear path is handled by moving the work into
status_clear_warning/error_slow_path_(): on a real set->clear transition
the helpers walk App.components_ once to check if any other component
still has the flag, and clear App.app_state_ if not. Clears are rare
relative to loop iterations (a logged transition event), so O(N) per
clear is far cheaper than O(N) per loop.

Setup subtlety: Application::setup()'s slow-setup busy-wait forces
STATUS_LED_WARNING on to blink the LED while a slow component initializes.
A component clear during setup would prematurely wipe that forced bit,
so status_clear_warning_slow_path_() gates its walk-and-clear behind
APP_STATE_SETUP_COMPLETE (a free bit on app_state_ — zero RAM cost).
Application::setup() reconciles the warning state once at the end and
sets the flag. STATUS_LED_ERROR is never forced so its clear path
always walks.

Also fixes a pre-existing bug: the old per-iter accumulation only iterated
looping_components_, so non-looping components' status bits would get
clobbered by the end-of-loop 'app_state_ = new_app_state' overwrite.
The walk-on-clear approach iterates components_ (all of them), so
non-looping components are respected.
2026-04-11 16:05:46 -10:00
J. Nick Koston 57592fa664 Merge remote-tracking branch 'upstream/feed-wdt-inline-fastpath' into integration 2026-04-11 15:22:33 -10:00
J. Nick Koston 5926ca5369 [core] Split feed_wdt into hot and cold entries
Separate Application::feed_wdt() into two entry points so the hot path
callers stop paying for the time==0 check they never trigger:

- feed_wdt_with_time(time): inline, hot path. Rate-limit check in 3
  Xtensa instructions (load + sub + branch). [[unlikely]] tells the
  compiler the slow branch is rare so the common path stays
  fall-through.
- feed_wdt(): cold, out of line. Fetches millis() and forwards through
  the same rate limit. Used by setup loops, upload helpers, yield(),
  and any other non-hot caller.

feed_wdt_slow_() is now pure worker code — 11 bytes. It just calls
arch_feed_wdt(), updates last_wdt_feed_, and runs the status LED
re-dispatch. Both entries have already confirmed the rate limit was
exceeded before calling.

Hot call sites updated:
- Application::loop() per-component feed
- Scheduler::execute_item_() after each scheduled item runs
- Application::teardown_components() inner loop (already has 'now')
2026-04-11 15:19:35 -10:00
J. Nick Koston 1815398062 Merge remote-tracking branch 'upstream/feed-wdt-inline-fastpath' into integration 2026-04-11 15:05:52 -10:00
J. Nick Koston dc5626eb85 [core] Invert feed_wdt condition so slow-path call is inside the if
Cleaner than the early-return form — the action (calling feed_wdt_slow_)
reads as the body of the conditional instead of falling through past a
guard clause. Logically identical and compiles to the same code.
2026-04-11 14:57:01 -10:00
J. Nick Koston 715f0ca6f7 [core] Extract WDT_FEED_INTERVAL_MS constexpr
Replace the magic 3 in both the inline feed_wdt check and the slow path
with a named constexpr so the rate-limit threshold is defined once.
2026-04-11 14:54:02 -10:00
J. Nick Koston a70ec9ec06 [scheduler] Feed watchdog after each scheduled item, drop top-of-loop feed
The main loop used to feed the watchdog unconditionally right after
Scheduler::call() returned, regardless of whether the scheduler had any
actual work to do. On an idle device this meant every outer loop
iteration paid the inline rate-limit check (load + sub + branch) for no
benefit.

Move the feed into Scheduler::execute_item_() so it fires only after a
scheduled callback actually runs, and covers both the main heap path
and the defer queue path (both go through execute_item_). This also
bounds the max feed gap during a burst of back-to-back scheduled items
by max(item_runtime) instead of sum(item_runtime).

The top-of-loop feed in Application::before_loop_tasks_() is now
unnecessary — when Scheduler::call does no work, the only elapsed time
is the sleep wake plus a few instructions, and when it does have work,
it fed the wdt as it went.
2026-04-11 14:51:59 -10:00
J. Nick Koston ddbf6f2347 [core] Inline feed_wdt hot path with out-of-line slow path
Split Application::feed_wdt() into an ALWAYS_INLINE wrapper that checks
the 3ms rate limit against last_wdt_feed_ and a feed_wdt_slow_() callee
that performs the actual arch_feed_wdt() + status LED re-dispatch.

Callers on the hot path (loop_task before/after each component) that
already have a millis() timestamp in hand now pay only a load + sub +
branch on the no-op path instead of a full call8 / entry / retw.

Moves the rate-limit state from a function-local static to a class
member (last_wdt_feed_) so the inline can access it.
2026-04-11 14:32:49 -10:00
Jonathan Swoboda bef4c8a86c [cc1101] Extract chip configuration into configure() method (#15635) 2026-04-11 17:36:27 -04:00
J. Nick Koston ea0ba99c28 [core] Drop stale register_socket defs after ota merge
PR #15639 removed Application::register_socket / monitored_sockets_
on the fast-select path before the ota-disable-loop-when-idle merge.
The merge re-introduced the function definitions without the matching
declarations. Drop them.
2026-04-11 08:40:17 -10:00
J. Nick Koston a6523fde47 Merge remote-tracking branch 'upstream/ota-disable-loop-when-idle' into integration
# Conflicts:
#	esphome/core/application.cpp
2026-04-11 08:36:24 -10:00
J. Nick Koston bfcfd7f110 Merge branch 'dev' into ota-disable-loop-when-idle 2026-04-11 08:28:06 -10:00
J. Nick Koston 30de0c17ab [esphome.ota] Trim verbose comments from simplification 2026-04-11 08:21:11 -10:00
J. Nick Koston e67fac704c [esphome.ota] Move OTA wake pointer out of Application into ota_esphome.cpp
Following the zephyr_mcumgr precedent, keep the single-instance pointer
as a file-scope static inside ota_esphome.cpp instead of plumbing an
ota_wake_component_ slot and setter through Application. The extern "C"
wake trampoline also lives in the same TU now, so nothing in core/
touches OTA-specific state.

Guard the C and C++ call sites on USE_OTA_PLATFORM_ESPHOME (added as a
-D flag from components/esphome/ota/__init__.py) instead of the broader
ESPHOME_USE_OTA that base ota/ used to emit — the trampoline symbol only
exists when the esphome OTA platform is actually compiled in.

Also drop the dead host yield_with_select_ wake hook (host has no OTA
platform today).
2026-04-11 08:17:49 -10:00
Farmer-shin 6e67864510 [epaper_spi] Add Waveshare 3.97inch E-Paper Display (#15466) 2026-04-11 21:27:25 +10:00
J. Nick Koston a977f99bb1 Merge remote-tracking branch 'upstream-ssh/status-led-disable-loop-idle' into integration 2026-04-11 00:16:56 -10:00
J. Nick Koston 7eb56e1cf6 [status_led] Clarify feed_wdt LOOP_DONE comment 2026-04-11 00:14:40 -10:00
J. Nick Koston 56029457f4 [status_led] Restructure feed_wdt to tail-call status_led loop() 2026-04-11 00:13:05 -10:00
J. Nick Koston f6311c3846 [status_led] Use millis() to survive blocking waits via feed_wdt 2026-04-11 00:07:22 -10:00
J. Nick Koston fcd1aa5a40 [status_led] Hoist state read and dispatch loop() directly from feed_wdt 2026-04-11 00:05:57 -10:00
J. Nick Koston 0f80c16507 [status_led] Skip feed_wdt dispatch entirely when idle 2026-04-11 00:03:55 -10:00
J. Nick Koston c9a68baa69 [status_led] Remove unrelated changes from application.cpp 2026-04-10 23:58:36 -10:00
J. Nick Koston af7fdc9887 [status_led] Simplify loop body, rely on disable_loop for idle optimization 2026-04-10 23:49:56 -10:00
J. Nick Koston 59d0f9dcbd [status_led] Disable loop when idle and switch blink timing to deadline-based 2026-04-10 23:44:35 -10:00
dependabot[bot] c2af4874f9 Bump aioesphomeapi from 44.13.2 to 44.13.3 (#15641)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 08:58:20 +00:00
dependabot[bot] 2001b91280 Bump resvg-py from 0.3.0 to 0.3.1 (#15640)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 08:57:39 +00:00
J. Nick Koston a76ed9cc77 Merge remote-tracking branch 'upstream/dependabot/pip/aioesphomeapi-44.13.3' into integration 2026-04-10 22:56:04 -10:00
dependabot[bot] f3357f47c6 Bump aioesphomeapi from 44.13.2 to 44.13.3
Bumps [aioesphomeapi](https://github.com/esphome/aioesphomeapi) from 44.13.2 to 44.13.3.
- [Release notes](https://github.com/esphome/aioesphomeapi/releases)
- [Commits](https://github.com/esphome/aioesphomeapi/compare/v44.13.2...v44.13.3)

---
updated-dependencies:
- dependency-name: aioesphomeapi
  dependency-version: 44.13.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-11 08:53:16 +00:00
J. Nick Koston d30d8f141f Merge remote-tracking branch 'upstream/core-remove-fast-select-pre-sleep-scan' into integration 2026-04-10 21:35:09 -10:00
J. Nick Koston 4fdd715004 [core] Fix stale forward reference to renamed helper
application.h was still pointing at fast_select_hook_fd in a doc
comment after 51316f61c9 renamed it to hook_fd_for_fast_select.
2026-04-10 21:35:00 -10:00
J. Nick Koston c007441098 Merge remote-tracking branch 'upstream/core-remove-fast-select-pre-sleep-scan' into integration 2026-04-10 21:33:47 -10:00
J. Nick Koston 51316f61c9 [socket] Rename fast_select_hook_fd -> hook_fd_for_fast_select
Disambiguates the verb-vs-noun parse of the original name. The new
form reads as 'hook this fd for the fast-select path', matching the
function's actual job.
2026-04-10 21:32:53 -10:00
J. Nick Koston e7892a34b1 Merge remote-tracking branch 'upstream/core-remove-fast-select-pre-sleep-scan' into integration 2026-04-10 21:28:10 -10:00
J. Nick Koston 87c0538884 [socket] Address Copilot review: tighten doc comments
- cached_sock_ comment in both impl headers: drop the 'iff' wording
  since the pointer can also be null if esphome_lwip_get_sock() fails
  on a fd that was requested to be monitored. Document all three null
  cases explicitly, plus the close()-path nulling for UAF protection.

- application.h register_socket_fd / unregister_socket_fd comment
  block: move inside the #ifdef USE_HOST so the generic
  'register/unregister a socket' wording no longer implies these APIs
  exist on fast-select builds. Add a forward reference to
  fast_select_hook_fd for readers wondering where the ESP32/LibreTiny
  equivalent went.
2026-04-10 21:27:23 -10:00
J. Nick Koston 7366f0a9d0 Merge remote-tracking branch 'origin/core-remove-fast-select-pre-sleep-scan' into integration
# Conflicts:
#	esphome/core/application.cpp
2026-04-10 21:16:05 -10:00
J. Nick Koston c192b4c266 Merge remote-tracking branch 'upstream/dev' into integration 2026-04-10 21:13:47 -10:00
J. Nick Koston 884dab4a6a [socket] Null cached_sock_ in close() to prevent post-close UAF
Restore the cached_sock_ = nullptr assignment inside close() on the
fast-select path. The lwip slot can be recycled for a new connection
as soon as the underlying close() returns, so any dereference of
cached_sock_ afterwards would touch an unrelated socket's pcb.

No current caller does this — setsockopt(TCP_NODELAY) and ready() are
the only consumers and neither is invoked post-close today — but
leaving the pointer dangling is a footgun for future changes. The
fd_ = -1 sentinel alone would catch the ready() path via closed
semantics, but setsockopt() reaches cached_sock_ directly and would
not be protected. Null the pointer so the protection is by
construction rather than by caller discipline.
2026-04-10 21:12:51 -10:00
J. Nick Koston b9541cd5db [socket] Eliminate closed_ and loop_monitored_ redundancy
Replace the separate closed_ bool with fd_ < 0 as the 'not open'
sentinel. close() now sets fd_ = -1 after the underlying close call,
so the destructor and double-close paths just check fd_ < 0. As a
side benefit, get_fd() on a closed socket now returns -1, making
use-after-close visible to callers instead of returning a stale
descriptor.

Drop loop_monitored_ on the USE_LWIP_FAST_SELECT path — the pointer
cached_sock_ already encodes monitoring state (non-null iff
monitored). On USE_HOST the bool is still needed because there is no
cached pointer to derive from.

Combined effect on the fast-select path:

  Before:  fd_(4) + cached_sock_(4) + closed_(1) + loop_monitored_(1)
           + pad(2) = 12 bytes per socket
  After:   fd_(4) + cached_sock_(4)
           = 8 bytes per socket (aligned, no tail padding)

Saves 4 bytes per Socket instance on ESP32/LibreTiny. With typical
workloads running 5-10 sockets (API listen + clients + mDNS) that's
20-40 bytes of RAM.
2026-04-10 21:05:21 -10:00
J. Nick Koston 107915fe36 [socket] Dedupe fast_select hook logic into shared helper
Lift the lwip_sock resolve + event-callback hook sequence into
socket::fast_select_hook_fd() in socket.h so the USE_LWIP_FAST_SELECT
constructor blocks in lwip_sockets_impl.cpp and bsd_sockets_impl.cpp
stop drifting in lockstep. Both impls now collapse to a two-line call
site.
2026-04-10 20:59:12 -10:00
J. Nick Koston 4a9d3da962 [core] fast_select scan removal: address review feedback
- Drop redundant cached_sock_ = nullptr assignment in close(). After
  closed_ = true the socket is a corpse and no ready() or other member
  access is valid, so the nulling is not load-bearing. The comment now
  explains why on both impl variants.

- Reword the yield_with_select_ comment so the wake-source sentence
  reads as a complete list rather than a trailing fragment.
2026-04-10 20:58:12 -10:00
J. Nick Koston 7ce49089a0 [core] Remove pre-sleep socket scan from fast select path
The pre-sleep scan in Application::yield_with_select_() walks
monitored_sockets_ on every loop iteration, issuing a volatile
cross-thread read on each socket's lwip_sock::rcvevent to preserve
select() semantics when the FreeRTOS task notification counter had
been consumed but a socket still had unread data.

That scenario only existed because of a Socket::ready() contract
violation: callers could stop reading with rcvevent > 0, leaving
data behind with no pending notification. That contract is now
documented and enforced (#15590), and #15589 (the first failure
that reverted the earlier removal attempt #14475) has been fixed.

With the contract honoured, every rcvevent > 0 is paired with a
pending xTaskNotifyGive from the lwip event_callback wrapper (see
lwip_fast_select.c). ulTaskNotifyTake either returns immediately
(counter non-zero) or wakes the moment the notify lands — the scan
has nothing left to rescue.

Evidence: https://github.com/esphome/esphome/pull/15638 — an
instrumentation PR ran across 5 devices (ESP32 rev1/rev3.1/C3 on
Ethernet and WiFi, plus LibreTiny RTL8720CF) through Home Assistant
disconnect/reconnect cycles, multi-client API logger bursts, and
BLE GATT connect storms. Across ~275,000 scans and 4 observed
load-bearing candidates, every hit was in the 2–14µs range — the
instruction-level window between the lwip callback writing
rcvevent and calling xTaskNotifyGive a few instructions later.
Zero hits exceeded 100µs. No hit came anywhere near loop_interval
(16ms), which is the latency scale the scan was added to prevent.

In addition to being unused, the scan is actively harmful on the
hot path: N volatile 16-bit loads against cache-cold cross-thread
lwip_sock structures on every main-loop iteration, just to
reproduce a microsecond-scale ordering artifact the notification
path is already handling authoritatively.

This also removes the now-unused monitored_sockets_ vector and
Application::{register,unregister}_socket() on the fast-select
path. Socket implementations now call esphome_lwip_hook_socket()
directly to install the netconn event callback wrapper.
2026-04-10 20:50:47 -10:00
J. Nick Koston b1d6eff17c Merge remote-tracking branch 'upstream/ota-disable-loop-when-idle' into integration 2026-04-10 17:48:19 -10:00
J. Nick Koston 82699a7ce3 [esphome.ota] Trim verbose comments
Per CLAUDE.md: comments should explain the non-obvious why, not narrate
the design journey. Remove the reasoning-aloud, before/after framing,
redundant restatements, and cross-file cross-references — the commit
messages and PR description already carry that context. Behavior
unchanged.
2026-04-10 17:47:36 -10:00
J. Nick Koston f8a1c54690 [esphome.ota] Document NULL-fallback degraded mode for listener filter
Per review feedback: if esphome_lwip_get_sock() ever returned nullptr
(shouldn't after successful listen(), but defensively), the listener
filter compare would never match and no fast-select wakes would fire.
loop()'s self-disable safety net + the first-tick-after-setup window
cover that degraded mode correctly. Spell it out in the comment so a
future reader doesn't treat the nullptr path as a silent bug.
2026-04-10 17:44:18 -10:00
J. Nick Koston f75d6ab88d [esphome.ota] Update docstrings to match post-filter behavior
Two doc-drift fixes flagged by copilot review:

1. esphome_fast_select_set_ota_listener_sock() header comment claimed
   passing NULL 'clears the filter' so wake fires on every RCVPLUS. The
   actual code stores NULL and the conn == s_ota_listener_conn check
   never matches, so NULL means 'no wakes' not 'all wakes'. Rewrite to
   describe the actual semantics (install a listener to enable filtered
   wakes; NULL disables OTA wakes entirely).

2. ESPHomeOTAComponent::loop() docstring still claimed false wakes from
   unrelated monitored sockets are expected. Post-filter that's no longer
   true on fast-select (filtered to OTA listener netconn) or raw TCP
   (per-pcb accept_fn_). Rewrite to describe the current behavior:
   loop() runs ~once per real incoming OTA connection, with the idle
   self-disable retained as a safety net for the few narrow cases where
   a wake can land with no pending work (queued-during-session, filter
   not yet installed, host select fallback).
2026-04-10 17:39:37 -10:00