meta-pass is a multi-firmware launcher I wrote for AI Passport. A persistent launcher sits on the device, firmware images are installed into Flash slots and you select which one to boot from a startup list instead of reflashing the whole device every time. The two-day MVP process is documented in the previous post.
Not useful. This thing takes up 3MB, leaving only two 2MB slots. Anything slightly practical won’t fit.
The comment was mostly right. Over the next six days, I submitted 90 commits, working through eight comments one by one and iterated meta-pass from MVP to v1.0: three slots, signature badges, backup and restore, single-file firmware, data-safe upgrades, bootloader hardening and a USB speedup. Most of the v1.0 changes were directly driven by those comments.
The Space Problem
The comment on September 12 pointed right at the core issue: the launcher took 3MB, leaving just two 2MB slots, which meant larger gameplay firmwares couldn’t fit.
The second MVP build produced an 8MB combined image, but over 80% of that was empty slot space. The actual firmware code was only a small fraction of the total, and reserving 3MB of Flash for the launcher image was wasteful. In v1.0, I ran compression optimizations and pushed the factory image down to under 1.44MB, freeing enough space to enlarge slot 0 to 1.84MB.

Once the factory image shrank, the previously unused gap in front of the cardid region on Flash could be put to work, providing enough space to fit a third slot.
A user on September 15 asked: Is each partition capped at 2MB? Can we assign sizes freely?
No. According to the manufacturer specifications, the cardid identity region is fixed in the middle of the Flash and cannot move. It splits the available space in half, and the addresses and sizes of all three slots are calculated from that fixed position. The gap in front holds 1.84MB, which became the first slot. The space behind cardid is aligned to 64KB boundaries; the second slot stays at 2MB, and the third takes the remaining 2.61MB.
The largest slot goes to the most space-hungry gameplay, and it can double as storage for a voice-recording firmware. Now the walkie-talkie, the radar treasure game and the third community project can all coexist on the device without deleting one before adding another.
Changed the Name, Still Booted as AI Passport
Someone changed the display name, but the device still displayed AI Passport when it booted up.
I traced the root cause and could not find a definitive answer. The display-name blob write logic had existed since the MVP release, so it should have worked. I do not know exactly which link in the chain broke, and I have no evidence to point to. I’ll admit it: the symptom was real, and the cause remains unclear.
v1.0 closes the loop completely. The USB install page now auto-fills the name with the gameplay’s English title or local filename, and the Wi-Fi import page gained an optional name input field. This scenario should not recur.

Can We Add a Bypass for Unsigned Firmwares?
Someone asked whether the long-press confirmation could be skipped for unsigned firmwares, saying the repeated pressing was annoying.
I’m not adding that option. The warning page is the last gate, and if it can be bypassed, the signature mechanism becomes meaningless.
But the long-press was genuinely awkward for new users. I changed it to a short press instead: the warning page pops up, you use the direction keys to highlight BOOT and you press OK to confirm. Because the default cursor sits on Cancel, a casual stream of OK presses does not accidentally boot an unsigned firmware. Signed firmwares skip the warning page entirely and boot immediately when you press OK.
Users Didn’t Understand How to Use It
Someone said they could not figure out how to use it, thinking they needed to install the downloaded gameplay firmware alongside meta-pass itself.
The market page did not explain the flow clearly enough. That is a content gap on the market side.
In v1.0, I rewrote the market introduction page for meta-pass and laid out the usage steps plainly: how to install, how to use, how to switch firmwares. Users should not have to guess.
Improvements Nobody Asked For
These next items were not prompted by comments, but they are all about making the launcher reliable and worry-free.
The install page can now package all slot firmwares, slot-attached data and the system storage area into a single zip. On restore, each item is validated against its fingerprint before writing; mismatched fingerprints are rejected, insufficient space is rejected explicitly and a partial write never leaves the device in a corrupted state. The system storage area is handled automatically: packed on backup, written back on restore, without the user needing to know what it is called.
Backups require reading entire slot regions, so transfer speed determines whether the feature is usable at all. Before the fix, reading a 1MB payload over USB took three minutes and failed frequently. After raising the baud rate to 921600 and adding a three-tier automatic recovery strategy (retry with resynchronization, downgrade speed, full link reset), a 1MB backup now completes in about one minute, and transient USB disturbances trigger automatic retries instead of forcing a restart.

Upgrading the launcher itself does not touch any data. The web page reads back the device partition table first and compares it byte-by-byte with the upgrade package; it then writes only the allowed regions: bootloader, partition table and launcher application. System storage, the identity region and all three slots are left untouched. Installed gameplay firmwares and user data survive intact.
The last item fixes an old wound from the MVP period. In the original rollback mechanism, a firmware specified its own persistent run policy. Under the old scheme, a gameplay compiled from an outdated template that declared a persistent run policy would lock the device inside that gameplay forever, with no error message and no way back even after power cycling. Moving the policy into the bootloader layer forces it to run before any firmware executes, and no gameplay can bypass it. A device stuck in that state recovers after a single power cycle once updated to this version.
Lessons From Six Days
Ninety commits in six days produce a few durable observations.
Do not leave Flash space on the table. The MVP combined image had 80% empty space. After compressing the factory image to under 1.44MB, the gaps on either side of the fixed cardid region could each absorb a slot, giving slot 0 a comfortable 1.84MB and slot 2 a generous 2.61MB. All of that came from reclaimed dead space.
More retries alone do not fix Flash read errors. Bumping retries from five to eight still dropped packets at the higher baud rates. The fix required three tiers: retry with resynchronization, fall back to a lower speed, then reset the entire link. Only with all three in place did the problem disappear.
NVS, cardid, slot and otadata are four different things. NVS stores Wi-Fi credentials and app configuration. The slot stores firmware images. The cardid stores the device identity and must not be touched. The otadata records which slot is currently selected. Corrupt any one of them during a launcher upgrade and you lose credentials, identity or boot selection in different ways.
Do not assume community firmwares follow conventions. Display names may be absent, signatures may be missing and unported firmwares will still run if given the chance. The protocol layer passes only the minimal information it needs and never pretends the other side will comply.
How to Get It
Search for meta-pass on the market, or visit the install page.
Source code and documentation: GitHub
References
- MVP development retrospective: Building a Multi-Cartridge Launcher for My Kid’s AI Toy
- meta-pass repository: alexwwang/meta-pass
- FoloToy market meta-pass page (source of user comments): ai-passport.folotoy.cn
