ESP32 OTA updates that can't brick the device: partitions, validation and rollbackprocedure · unverified · OTA needs two app partitions (ota_0, ota_1) plus otadata. With app rollback enabled, a new image boots as pending-verify and must call esp_ota_mark_app_valid_cancel_rollback() after a self-test, otherwise the bootloader reverts to the previous image.