|
SDK for TESAIoT Dev Kit
API reference & tutorials (ModusToolbox)
|
Each prebuilt archive under template/lib/<module>/ ships two machine-derived manifests next to its headers: consumer_must_provide.txt — symbols the archive calls back into and you must define — and overridable.txt — WEAK symbols you may override with a strong definition. Neither list is a call surface. Line counts below were read from the shipped files on 2026-08-28.
consumer_must_provide.txt (182 symbols). Three families matter:
overridable.txt: empty. Exported-but-undeclared (bento_secure_undeclared.h): consumers hand-write extern for calculate_idle_percentage, disp_touch_i2c_controller_context, g_tesaiot_display_diag, rtos_cm55_gfx_task_handle, tesaiot_display_ready — as the real callers do (proj_cm55/main.c:132-147, cm55_sensor_poll.c:42-54, lv_conf.h:1011-1017). Note: the shipped bento_secure_undeclared.h is stale for g_tesaiot_display_diag and rtos_cm55_gfx_task_handle, which tesaiot_display.h in the same directory does declare.
consumer_must_provide.txt (58 symbols): the RTOS and ML runtime the engine calls back into. The reverse relation is the useful one — cm55_core/consumer_must_provide.txt lists 35 ai_* symbols, which is exactly the set of edge_ai API functions with a shipped caller. The two API functions absent from it, ai_engine_dq_calls and ai_engine_resume_sensor, have no caller anywhere; their examples are authored. overridable.txt: empty. printf/puts are exported no-op stubs (Appendix X #1).
overridable.txt is exactly seven names, and every one is something you implement, never call:
| Hook | Template override | Contract |
|---|---|---|
| cm55_controls_snapshot | cm55_sensor_poll.c:342 | Fill the controls block for the sensorhub snapshot |
| game_sprite_create | game_sprite_engine.c:16 | Sprite engine seam |
| game_sprite_set | game_sprite_engine.c:25 | Sprite engine seam |
| game_sprite_lookup | game_sprite_registry.c:52 | Registry seam; feeds ui_widget_mgr_set_sprite_image |
| ipc_ui_ext_dispatch | ipc_ui_ext_chain.c:41 | Runs in GFX-task context; may touch the display (ipc_ui.h:40-41) |
| ipc_ui_ext_clear_all | W in libbento_ipc.a | Override point of the ext chain |
| ipc_ui_platform_diag | strong def archived, tesaiot_display.c:593-609 | max_words >= 10, returns 10; surfaced as ui._diag() |
consumer_must_provide.txt (302 symbols): LVGL, PDL IPC pipe, FreeRTOS, and the page-manager seam. Archive hazard: PROVENANCE.txt bakes PAGE_ID_PLAYGROUND == 7.
overridable.txt: empty — nothing weak inside the archive. consumer_must_provide.txt (71 symbols): MQTT objects, OPTIGA primitives (optiga_util_*, optiga_crypt_*), the touch IPC, base64, and optiga_util_callback, which the consumer supplies to optiga_manager_init(). Separately, six of the 18 API functions are consumed as weak symbols by shipped callers under ENABLE_OPTIGA_CLM=1 and need a function-pointer NULL check before the call (Appendix X #19).
overridable.txt: app_wifi_connect_direct, app_wifi_disconnect, app_wifi_get_ipv4, lfs_load_wifi_creds, lfs_save_wifi_creds. Template strong definitions in proj_cm33_ns/wifi_init.c at :193, :248, :256, :261, :304 respectively (mapping adjudicated in RED round 1). Their zero template call sites are correct — implement, do not call. lfs_save_wifi_creds takes no wifi_creds_lock (Appendix X #18). consumer_must_provide.txt (61 symbols): WCM/WHD, the IPC pipe, FreeRTOS, and the OPTIGA fingerprint helpers.
If a name is in overridable.txt, a reference page that says "call this" is wrong. If a name is in consumer_must_provide.txt, the archive will not link until you define it — and the shipped template already does, which is why the lists read as a map of what you own.