From 6faed242f2b8d991ef895f2c494d296aaeb71fff Mon Sep 17 00:00:00 2001 From: "J. Nick Koston" Date: Fri, 18 Sep 2026 15:49:04 -0500 Subject: [PATCH] Say the current key applies once the firmware has booted, warn when old_key was the key that worked --- esphome/espota2.py | 11 +++++++++-- tests/unit_tests/test_espota2_noise.py | 3 +++ 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/esphome/espota2.py b/esphome/espota2.py index 3e7b5540855..bcb0ad2c324 100644 --- a/esphome/espota2.py +++ b/esphome/espota2.py @@ -241,8 +241,8 @@ PLAINTEXT_FALLBACK_NOTICE = ( OLD_KEY_REMOVE_NOTICE = ( - f"The device now runs the current key; remove '{CONF_OLD_KEY}' from " - "'ota: encryption:'" + "Once the device has booted this firmware it runs the current key; remove " + f"'{CONF_OLD_KEY}' from 'ota: encryption:'" ) @@ -992,6 +992,13 @@ def run_ota_impl_( _LOGGER.error(str(err)) return 1, None + if encryption.tried_old_key: + # Kept next to the result: a device that should already run the + # current key but answered to the previous one is worth a look + _LOGGER.warning( + "The device accepted '%s'; it was still running the previous key", + CONF_OLD_KEY, + ) return 0, sa[0] _LOGGER.error("Upload failed after %d attempts: %s", total_attempts, last_error) diff --git a/tests/unit_tests/test_espota2_noise.py b/tests/unit_tests/test_espota2_noise.py index f674032437a..ca50641309b 100644 --- a/tests/unit_tests/test_espota2_noise.py +++ b/tests/unit_tests/test_espota2_noise.py @@ -310,6 +310,9 @@ def test_old_key_retry( assert ( any("retrying with 'old_key'" in r.message for r in caplog.records) is retried ) + assert any("accepted 'old_key'" in r.message for r in caplog.records) is ( + retried and expected_rc == 0 + ) assert not any("plaintext" in r.message for r in caplog.records) if expected_rc == 1 and old_noise_psk is not None: assert any("rejected both" in r.message for r in caplog.records)