OrcSDR v0.3.0-beta.1 — release notes
Prepared 2026-09-28. Previous release: v0.2.0-beta7.
These notes are written in plain language on purpose. They say what changed, what broke along the
way (including things we broke ourselves), what we still know is wrong, what we did not test, and
who helped. The current, authoritative evidence table is PROJECT_STATUS.md;
these notes are a dated record and do not override it.
The short version
OrcSDR turns an M5Stack Tab5 and an RTL-SDR USB dongle into a touch-screen radio scanner. This is a
beta: it works, we use it, and it is still changing.
The big things in this release:
- Three dongles are recognised and given their own controls: the RTL-SDR Blog V4, V4L and
V3/V3c. The V4L is recognised properly, and each dongle's own gain steps, bias-T safety and tuner
bandwidth are handled by a newly published driver. This does not mean all three are equally tested: the
V4 is the longest-tested baseline, and the V3c and V4L were each checked on a single unit (see
"What we tested, and what we did not"). - Changing the tuner bandwidth no longer moves the radio to the wrong frequency. In RF Lab,
stepping NEXT BW used to slide the spectrum sideways (by about 95 kHz on the V3c and up to about
390 kHz on the V4L) while the screen still said the same frequency. That is fixed and was tested on
all three dongles. - A new gain panel on the Home screen, with SMART and MANUAL gain, tuner AGC and RTL AGC.
- CB radio no longer has AM ghosts on it. A strong AM station could show up on a CB channel; the V4
and V4L now tune CB directly. - A faster, calmer DSP path. The FM stereo + RDS load fell from about 68% to about 45% of the
processor, and overload no longer resets the Tab5. - Plug in a dongle whenever you like. Plugging in, replugging or swapping a dongle now starts
receiving, instead of leaving you with a silent screen. - A new band-wide CB scanner, browser audio in the web console, a more complete Shortwave dashboard,
an SD card that writes about 15 times faster, and a Wi-Fi/C6 link that recovers by itself. - Smoother FM screen, a bigger keypad and keyboard, a friendlier start-up sequence, and a long list of
fixes below.
At a glance
| Release | OrcSDR v0.3.0-beta.1 (beta: works, still changing) |
| Previous release | v0.2.0-beta7 (2026-09-16) |
| Device | M5Stack Tab5 (ESP32-P4; tested on revision 1.3), with the ESP32-C6 radio for Wi-Fi |
| Radio dongles | RTL-SDR Blog V4 (the tested baseline), V4L, V3/V3c. Nooelec NESDR SMArt v5 is provisional |
| Driver | esp_rtl_sdr v0.9.1 (commit 105caa56b9b5ce395a7b4910c6f703c14b83b5d9)
|
| Wi-Fi radio firmware | ESP-Hosted 3.0.6 on both processors (a 3.0.6 C6 image is inside the package) |
| Built with | ESP-IDF 5.5.4 |
| Source commit | 1d1bf64 (merge of #115)
|
| Size of the change | 96 commits since beta7, 197 files, +27,243 / −2,476 lines |
Downloads and how to check them
| File | What it is | SHA-256 |
|---|---|---|
OrcSDR-Tab5-v0.3.0-beta.1.bin
| The complete Tab5 image (bootloader, partition table, application) used for the M5Burner listing. The C6 update image is embedded inside the application. | b10d726f0a3d05599836a04c4fa634f3e016b4474d29186f216cce7dcbdc65ed
|
OrcSDR-Tab5-v0.3.0-beta.1-installer-windows-amd64.zip
| Settings-safe installer for Windows (keeps your Wi-Fi and settings). Unzip and double-click install.bat. No Python needed. 16,833,422 bytes
| 628a7d5e3f4d9b88a533d3925995ad36e98c72e6aa1ab440a224bc918e3a3636
|
SHA256SUMS.txt
| The checksum list for the files above |
This is the exact file that was uploaded to M5Burner, built from the tagged commit. Check your download
before you flash it. On Windows (PowerShell):
Get-FileHash .\OrcSDR-Tab5-v0.3.0-beta.1.bin -Algorithm SHA256On Linux:
sha256sum OrcSDR-Tab5-v0.3.0-beta.1.binOn macOS:
shasum -a 256 OrcSDR-Tab5-v0.3.0-beta.1.binThe result must equal the SHA-256 in the table. If it does not, do not flash it. The checksum proves your
download is the same file we published; it cannot tell you the published file is complete. The
application-only mistake we made on beta7 (#93) is caught by
the size: this complete image is 3,812,384 bytes, while an application-only file is smaller.
Version numbers: why v0.3.0-beta.1?
Our old tags were inconsistent (beta.6, beta7, and experimental -rc builds that were not really
release candidates), and some of them sort in the wrong order. From this release we follow one written
rule set, docs/VERSIONING.md:
v0.3.0-beta.1= the third minor version, first beta build. Dotted stage numbers sort correctly.- A new minor version because the release adds real capability (new dongle support, the gain panel, the
driver 0.8 → 0.9 jump). - Releases now pin a published
esp-rtl-sdrrelease, not a loose branch. This one uses
esp_rtl_sdr v0.9.1. Development builds may pin a branch and commit.
Before you install
- To keep your saved settings, use the settings-safe installer (
OrcSDR-Tab5-v0.3.0-beta.1-installer-windows-amd64.zip, see Installing, step by step). Your saved settings will be reset if you install through M5Burner. Installing through M5Burner (even without erase) wiped the
Wi-Fi profiles, location, screen rotation and other saved settings on the test Tab5
(#117). This has apparently always been the case with
the M5Burner package, and our earlier notes saying otherwise were wrong. Write down your Wi-Fi details
first and expect to re-enter them. We intend to fix this properly. - Then open Settings → Firmware & Updates and let it check the C6 radio firmware. It should report
ESP-Hosted3.0.6on both processors (host=3.0.6 coprocessor=3.0.6 match=1). - The M5Burner listing went public before the package hardware gate was finished; see "What we tested, and what we did not" for what has and has not been checked on the installed package.
- A note on the last release: the first
v0.2.0-beta7download was accidentally an application-only
file even though the instructions said it was a complete image, so it left one user with a black
screen (#93). It was replaced in place once we
knew. Our release checklist now includes downloading every published file back and checking it.
Installing, step by step
Option A: settings-safe installer (Windows, keeps your settings)
- Download
OrcSDR-Tab5-v0.3.0-beta.1-installer-windows-amd64.zipfrom this page and unzip the whole folder. - Plug the Tab5 into the PC with a USB-C data cable and switch it on.
- Double-click
install.bat. It checks every file, shows the connected devices (if there is more than one, you choose; it never guesses), confirms the device really is an ESP32-P4, and writes only the program. It never erases anything and never writes your settings area or the C6 Wi-Fi radio. - Wait for DONE. The Tab5 restarts by itself and your Wi-Fi and settings are still there.
The installer was checked on a real Tab5: before and after, the saved Wi-Fi profile, the connection and the event-journal count were unchanged. It includes Espressif's esptool v5.4.0 unmodified (GPL-2.0-or-later; license in the zip). There is no Linux or macOS installer on this release yet.
Option B: M5Burner (resets your settings)
- Write down what you need to keep. An M5Burner install resets saved settings (see the first bullet above; the installer in Option A does not):
Wi-Fi network names and passwords, your location, and screen rotation. Take a photo of the settings you
care about. - Use M5Burner with OrcSDR and the Tab5. Do not use any "erase" option. (Erasing is not what
resets your settings; the install does that anyway, see #117.) - Wait for the Tab5 to restart on its own. Do not unplug it while it writes.
- The first start shows the OrcSDR splash and names each start-up step. If nothing is plugged into the USB
port, or the network is not set up yet, the steps time out and you still reach the OrcSDR button. Home
opens by itself after 30 seconds. - Plug in your RTL-SDR dongle at any time. It will start receiving on the current band.
- Open Settings → Firmware & Updates. It should show ESP-Hosted
3.0.6on both processors and
current. If it offers UPDATE C6 TO 3.0.6, confirm it and leave the Tab5 alone until it restarts. - Re-enter your Wi-Fi, location and rotation.
First-boot checklist
- Home appears and the touch screen responds
- The Home screen names your dongle (
RTL V4,RTL V4LorRTL V3c) - FM audio plays and the spectrum moves
- Firmware & Updates reports
host=3.0.6 coprocessor=3.0.6 match=1 - Wi-Fi scan finds networks, and a saved profile connects
- RF Lab NEXT BW changes the shown bandwidth and the signal stays on the same frequency
If a step fails, see Troubleshooting below and tell us (How to report a problem).
Coming from v0.2.0-beta7
- Your saved settings will be reset by the install (see above).
- The driver changed from the
0.8.0-rc4controls to the publishedesp_rtl_sdr v0.9.1. The public driver
interface did not change, but the V4L is now recognised as its own dongle and each dongle uses its own
gain steps. - The Home screen has a new GAIN panel, RF Lab NEXT BW now keeps the radio on frequency, and
CB radio has a full scanner screen. - The boot sequence is different (embedded splash, staged start-up, an OrcSDR button, Home after
30 seconds).
What is new
Dongles and hotplug
- V4L support. The Home screen names each dongle correctly (
RTL V4,RTL V4L,RTL V3c), and RF
Lab's hardware notes now follow whichever dongle is plugged in instead of assuming a V4. - Start receiving whenever a dongle appears. Previously a dongle plugged in after boot, replugged
while idle, or swapped for another sat ready but silent. Now it starts on the current band. (Wi-Fi
scans and other exclusive jobs still pause the radio first, then it resumes.) - No dongle? Screens still work. Opening ADS-B, LoRa, POCSAG and the other dashboards with no dongle
attached used to leave you on a screen you could not leave; every dashboard now opens and responds. - A band your dongle cannot tune (for example V4L below 24 MHz without the up-converter route) now
still switches the screen, instead of leaving FM's controls showing while your touches retuned FM. - V3/V3c AM: the RTL AGC is now available on the V3c's direct-sampling AM path.
Gain
- New Home gain panel: tap the GAIN box. Depending on the band you get SMART (FM/AM) or TUNER AGC,
MANUAL on your dongle's own gain steps (29 on the V4L and V3c, 28 on the V4), and RTL AGC. - SMART / MANUAL toggle on FM and AM: switching to MANUAL keeps the current gain, so the level does
not jump. RTL_GAINserial command (STATUS,AUTO,SMART,MANUAL <0..496>,RTLAGC ON|OFF) drives the
same path as the screen.- Bias-T safety: an extra warning for generic V3-family identities, any receiver change cancels a
previous acknowledgement, and leaving RF Lab can only turn the bias-T off.
RF Lab and tuner bandwidth
- NEXT BW steps through the widths the driver offers for the dongle and shows what was requested
and what was applied (a queued request is not shown as applied).RTL_DRIVER BW <hz|0>does the same
from the serial console. - RF Lab's sample-rate control now reaches 3.2 MS/s. That is for IQ capture experiments; it does not
give you audio (see Known issues).
CB radio: no more AM ghosts
- Direct route. Through the dongle's 28.8 MHz up-converter, a strong AM station at frequency f
also appears at 28.8 MHz − f, so the 1600 kHz AM station was heard on CB channel 20. The V4 and V4L now
tune the CB band directly (as the V3c already did), and on both the ghost was gone. You can override the
choice for testing withRTL_DRIVER HFDIRECT AUTO|OFF|<hz>.
Screens and audio
- FM Listen no longer flickers. It used to clear and redraw its whole centre column every 150 ms; now
each widget repaints only when its own value changes. - RDS radio text wraps to two centred lines instead of running under the level panels.
- The stereo VU moves. It used to meter after the automatic gain limiter, where every block looks the
same, so it sat still. - No more hiss with no dongle. The audio codec stays powered down until a receiver is present.
- A friendlier start-up: SD card, then Wi-Fi (waiting up to 25 s if the first join fails and retries),
then the USB port, then an OK button. Every step has a time-out, so a missing SD card, network or dongle
still reaches the button. - Larger keypad and keyboard. FM, shortwave and AM direct tuning share one bigger keypad, and AM has a
DIRECT TUNE button. - Each receiver is labelled on screen so you can tell which dongle a control belongs to.
Speed and stability
- Stage-1 DSP optimisation. The radio's signal processing was made cheaper without changing what it
computes. At 2.4 MS/s the load fell: FM stereo + RDS 68% → 45%, AM 52% → 35%, CB AM 51% → 35%, and RF
Lab/CB 67% → 45%. We proved the output did not change by running the old and new code on the same saved
radio samples: the audio bytes and the internal state were bit-for-bit identical for FM, narrow FM,
weather, AM and CB AM/LSB/USB. - Overload no longer resets the Tab5. When the signal processing fell behind, it never gave the rest
of the system a turn, and the watchdog rebooted the device (seen on AM at 2.4 MS/s, in CB, and in RF
Lab). It now backs off briefly, so overload shows up as dropped samples you can see, not a reboot.
Per-stage timing and load are now visible through the serial console. - A dongle that drops out while it is being set up no longer reboots the Tab5 (a driver fix).
CB radio: a band-wide scanner
CB now has its own dashboard. Because the radio streams 2.4 million samples per second, one look at the
spectrum covers the whole CB band (26.965 to 27.405 MHz) from any tuned channel. Every frame, the scanner
measures all 40 channels against the band's noise floor, stops on a channel that is talking, stays while it
stays active, waits a hang time for a reply, then carries on scanning.
- Five tabs: LISTEN (now-playing card, S-meter, scan controls, live activity bars for all 40 channels;
tap a bar to tune), SPECTRUM (whole band with channel ticks; tap to tune), ACTIVITY (channels on the air
now and a log of the last transmissions), CHANNELS (lockout grid with presets for all 40 and for SSB 36 to
40 only) and SETUP (mode, clarifier, squelch, threshold, hang time, maximum hold, priority, automatic
sideband). - Channel 9 is the default priority channel and interrupts other traffic. Channels you lock out are skipped.
- Automatic sideband: LSB on channels 36 to 40, AM on 1 to 35.
- It keeps scanning while CB plays behind the Home screen, and stops when you open another band.
- Your last channel, mode, clarifier, squelch, scanner settings, lockouts and whether scan was on are remembered.
- Serial control:
RTL_CB STATUS|ACTIVITY|SCAN ON|OFF|CHANNEL n|LOCKOUT n ON|OFF, andRTL_UI OPEN CB.
The scanner's logic has host tests (channel plan, level extraction, hysteresis, stop/hang/resume, priority,
lockout, skip, hold), and the owner reports it works on the V3c. A formal, recorded Tab5 RF acceptance of
the scanner has not been done, so PROJECT_STATUS.md still lists it as regression-tested only. More in
docs/cb/README.md.
Listen in your browser (LAN web console)
The optional LAN web console can now stream the radio's audio to a browser, separately from the Tab5's
own speaker.
- A LISTEN HERE control with buffering, automatic reconnection and playback status; it stops cleanly
when the page is hidden. - Muting or changing the volume on the Tab5 no longer changes what the browser hears, and the other way
round (#68). Each browser has its own position in the audio stream. - The audio held up: in a 10-minute test at 2.4 MS/s the browser received about 47,968 samples per second with
zero gaps and zero resets, which addresses #69 (choppy web audio).
Removing a delay that ran after every block of radio samples is what made sustained 2.4 MS/s possible. - The Home spectrum and waterfall stay live while the web console is open, and the spectrum uses a lighter
binary format. - Commands are validated, the browser's origin is checked, and busy or invalid commands get a clear answer.
- Trusted networks only. The web console has no TLS and no login.
Shortwave dashboard (phase 2)
The Shortwave screen gained the tools you need to explore the bands:
- Frequency and mode guidance, discovery, schedule and a bounded hunt for stations.
- Memories and a logbook, saved to the SD card.
- Spectrum zoom, pinch gestures and draggable filter edges, plus frequency labels.
- CLEAN, BOOST, NR, NOTCH and SQL audio controls.
- A direct-tune keypad that no longer hides behind other layers.
It has host regression tests and physical checks of the SD storage. PROJECT_STATUS.md still marks
Shortwave Experimental: a calibrated, complete HF AM/SSB experience is not claimed.
The SD card is about 15 times faster
Writing to the SD card on the Tab5 was crawling at about 0.30 MiB/s. The cause: large buffers in
the Tab5's extra memory were not aligned the way the SD hardware's DMA needs, so the operating system used
its slow fallback path. Aligning them raised sustained writes to 3.9 to 4.5 MiB/s (13 to 15 times faster,
measured on the Tab5 with a 40 MHz, 4-bit SDHC card). Recordings, IQ captures and Shortwave memories all benefit.
Details: docs/TAB5_SD_PERFORMANCE.md.
Wi-Fi and the C6 radio are much sturdier
- Wi-Fi at boot now connects reliably. Starting Wi-Fi no longer restarts the radio in the middle of a
connection attempt. In 10 test boots the connection succeeded 10 out of 10 times (it was 1 out of 10).
If the first attempt is refused right after the C6 starts, the retry a few seconds later succeeds. - Automatic reconnect. With auto-connect on, failed attempts and unexpected drops are retried after
3, 10, 30, 60 and 120 seconds. Turning Wi-Fi off or disconnecting yourself stops the retries. (Reconnect
after a real link drop, with the access point turned off and on, was not verified when this was written.) - A dead C6 link is now noticed and repaired without a restart (#106).
Overnight, the link between the Tab5 and the C6 died and the firmware never noticed: it kept trying, each
try froze the screen for 5 seconds, 4,649 times over 6.7 hours. Now the failure is detected, the radio
pauses, the C6 is power-cycled, and Wi-Fi comes back. It will do this up to three times until the link has
stayed up for 5 minutes; after that, the screen asks you to restart Wi-Fi. We tested it by cutting the C6's
power four times: three recoveries worked, and the fourth stopped at the limit by design.
We still do not know why the link died in the first place. It was seen once. - A crash while starting Wi-Fi is fixed (#103). A helper
task in the ESP-Hosted code could free memory that its creator was about to write into. Before the fix, 7 of
10 boots panicked in our test; after it, 20 of 20 were clean. - The C6 version is read at start-up even with Wi-Fi off (#82).
Start-up and reliability
- The dongle is found after a warm reboot. A Tab5 restart does not switch off the power to the USB-A
port, so a dongle that stayed powered could be missed. If none is found in time, the port is now
power-cycled for one second and detection retried; the dongle was found on 50 of 50 test boots. - The boot splash is built into the firmware (the old SD animation and its tools are gone). Each step is
named, the radio starts during the splash, and Home opens on its own after 30 seconds. - Each band remembers its own frequency after a reboot, without the brief tune to 99.130 MHz.
- Shortwave screens no longer flash during the start-up self-check.
- Less internal memory is used by things that do not need it, which leaves more room for the radio and Wi-Fi.
Data packs and the offline catalog
- Checking or installing a data pack while Wi-Fi is off now says Wi-Fi is required
(#87), and no longer pauses the radio first. - Data packs already on the SD card (for example the FAA databases) are reported as installed without a
catalog check.
Higher acquisition rates (experimental)
The driver delivered 2.40, 2.56, 2.88 and 3.20 MS/s in tests. That is raw radio sample transport only. We
also tried building better exact-rate frontends so audio could work above 2.4 MS/s. They are
experimental, compiled out of the normal firmware, and not used; WFM audio stays at 2.4 MS/s.
For developers
- A dongle gate for the UI regression script that captures a second of raw radio samples at every
step, checks them against the device's own checksum, and measures the carrier position and passband.
Plus a clean-room tool for recording and decoding the official PC driver. See
apps/orcsdr-tab5/tools/rtl-gate/README.md. - The full investigation report,
docs/testing/v3c-tuner-bandwidth-transition-2026-09-28.md,
with logs, plots and raw-sample checksums indocs/testing/evidence/.
Which dongles work, and how well tested is each?
| Dongle | Status in this release | What we actually tested |
|---|---|---|
| RTL-SDR Blog V4 | Tested baseline. The main release receiver | Streaming, FM/RDS, gain, CB direct route, hotplug, and the tuner-bandwidth cycle (carrier within 1.4 kHz; on the installed package within 1.2 kHz, but one bandwidth step failed once, see the gate record below) |
| RTL-SDR Blog V4L | Hardware-verified, experimental | One unit: recognised as a V4L, streamed FM at 96.1 MHz, passed the tuner-bandwidth cycle (carrier within 2.5 kHz in the earlier runs; on the installed package within 3 kHz after a hot-swap and within 3.7 kHz on a second cold boot; one cold boot read up to 7.8 kHz at 200k and 300k and did not repeat; see the gate record below) |
| RTL-SDR Blog V3 / V3c | RF-verified, experimental | One unit: detection, streaming, FM/RDS, retune, hotplug, USB and battery boot, and the tuner-bandwidth cycle (carrier within 2 kHz). Gain and sensitivity comparisons are provisional |
| Nooelec NESDR SMArt v5 | Provisional | Detection and streaming only; repeatable RF reception is not verified (#77) |
"Experimental" means it works in our tests but has not been through broad, repeated acceptance. The
authoritative table is PROJECT_STATUS.md.
An RTL-SDR Blog V4 is still the dongle we recommend for the least surprises.
How to use the new things
The gain panel (Home)
Tap the GAIN box on Home. What you see depends on the band:
- SMART (FM and AM): the radio picks a sensible gain for you.
- MANUAL: choose from your dongle's own gain steps (29 on the V4L and V3c, 28 on the V4). Switching to
MANUAL keeps the gain you have now, so the volume does not jump. - TUNER AGC and RTL AGC: automatic gain in the tuner chip and in the RTL2832 chip.
Tuner bandwidth (RF Lab)
Open RF Lab and tap NEXT BW to step through the widths your dongle offers (for example AUTO, 200k,
300k, 500k, 1.0M, 1.8M, 2.4M on the V3c). The screen shows the width you requested and the width the
driver applied; a request that is still queued is not shown as applied. Narrower settings cut the
side of the spectrum; going back to AUTO restores the full passband. The frequency should not move.
The widths are the vendor driver's control settings, not measured filter widths.
Serial commands (for testing and scripting)
Connect to the Tab5's USB serial port and pair (see
docs/API_SERIAL_CLI.md). Useful commands:
| Command | What it does |
|---|---|
RTL_DRIVER STATUS
| Driver version, dongle profile, streaming state, gain, bandwidth requested and applied |
RTL_DRIVER BW <hz or 0>
| Set the tuner bandwidth (0 = AUTO) |
RTL_DRIVER HFDIRECT AUTO, OFF or <hz>
| Choose whether 24 to 28.8 MHz uses the direct route (V4 and V4L) |
RTL_GAIN STATUS, AUTO, SMART, MANUAL <0..496>, RTLAGC ON or OFF
| Same gain controls as the screen (values in tenths of a dB) |
RTL_CB STATUS, ACTIVITY, SCAN ON or OFF, CHANNEL n, LOCKOUT n ON or OFF
| Drive the CB scanner |
RTL_UI OPEN CB
| Open the CB dashboard |
RTL_HEALTH
| Memory, tasks and reset reason |
RTL_WIFI_STATUS, RTL_WIFI_C6_STATUS
| Wi-Fi and C6 state, and the ESP-Hosted versions |
RTL_SPLASH_GATE ON or OFF
| Whether the boot splash waits for the OrcSDR button (turn it OFF for unattended reboot tests) |
Some commands only work after you authenticate. RTL_WIFI_C6_POWER OFF cuts the C6's power to test
the recovery described above: use it only for testing.
The driver: what changed in esp_rtl_sdr 0.9.1
OrcSDR talks to the dongle through the separate open-source driver
esp-rtl-sdr. This release pins its published release
v0.9.1 (its release notes
have the full story). The highlights:
- V4L recognised properly. It uses a different tuner chip (R828S) that answers like the V3's chip, so it
used to be set up as a V3. The driver now reads the dongle's name. - V3c, V4L and V4 controls copied from the official PC driver, measured with a USB analyser: gain steps,
tuner AGC, RTL AGC, bias-T and tuner bandwidth. - Direct HF route (V4, V4L, 24 to 28.8 MHz). Through the built-in 28.8 MHz up-converter a strong AM
station at frequency f also shows up at 28.8 MHz − f; the 1600 kHz station was heard on CB channel 20.
The direct route removes it. It is off by default in the driver, and OrcSDR turns it on for CB. - V3/V3c streaming soak-verified: 787 seconds at 1.024 MS/s beside a V4 at 2.4 MS/s, with no transfer
errors and no rejected setup commands. - USB reliability: a halted transfer endpoint no longer silently ends the stream while it still says
"streaming"; a skipped device close no longer loses the handle; unplug, replug, swap and two dongles on one
bus behave better; a dongle that drops out during setup no longer reboots the Tab5. - The tuner-bandwidth frequency shift fix described below, plus an out-of-bounds read of the bandwidth list
on the direct HF route, found by an automated code review. - Written down for the first time: how driver versions are chosen and released
(docs/VERSIONING.md).
There is deliberately nov0.9.0tag; that changelog entry was never published, and 0.9.1 contains it.
The big story: the frequency that moved
In RF Lab, NEXT BW changes the analog filter in the dongle's tuner chip. Doing that correctly means
changing three linked things at once: the tuner's filter, its internal frequency, and a matching
frequency setting inside the RTL2832 chip that turns the signal into samples. The screen kept saying
96.1 MHz because that is what we asked for, but the RTL2832's setting ended up slightly wrong, so the whole
picture slid sideways and half the spectrum looked cut off. A frequency step or a reboot repaired it.
The fault was in the driver, esp-rtl-sdr (release notes).
We found it by capturing raw radio samples after every step, recording what the official PC driver does
with a USB analyser, and reading the tuner chip's registers back. There were two separate bugs:
- The three bytes of the RTL2832 frequency setting were written back-to-back; the PC driver reads a
status register after each byte. Adding the reads fixed the shift on the V3c, V4L and V4. - On the V3c only, returning to AUTO bandwidth wrote filter settings that the V3c never uses at start-up,
leaving half the passband quiet. AUTO now restores exactly the start-up state.
Results (same station, same steps; the V3c from a cold boot, the V4L and V4 after being swapped in, and all three after unplugging and replugging the dongle; the first V4L cold boot with the dongle attached is in the gate record below):
| Dongle | Frequency error before | Now | Passband back to normal after AUTO |
|---|---|---|---|
| V3c | about ±95 kHz | within 2 kHz | within 0.8 dB in the pre-release runs (one run 3.6 dB, 0.4 dB when repeated); on the installed package the AUTO level differed from start-up by 0.3 to 2.1 dB lower (cold boot) and 0.9 to 4.4 dB higher (hot swap) |
| V4L | −312 to +386 kHz | within 2.5 kHz in the earlier runs; on the installed package within 3.7 kHz, except one cold boot that read up to 7.8 kHz at 200k and 300k and did not repeat | within 0.5 dB (0.7 to 1.2 dB on the package cold boot) |
| V4 | not measured | within 1.4 kHz in the pre-release runs (within 1.2 kHz on the installed package) | within 0.4 dB (within 0.2 dB on the installed package) |
Every pre-release run also had one retune per step, no radio restarts, no rejected commands, no USB overruns, and no
dropped samples or audio. The one exception is on the installed package (below): during one V4 hot-swap run a
single tuner write was rejected at the 1.8M step and the width stayed at 1.0M; six repeats of that step all worked.
Regressions and mistakes, told honestly
- The frequency shift was there from the day live tuner bandwidth was first added (September 25). We
did not measure the V4 before the fix. - The V3c passband problem after AUTO was our own regression, introduced on September 28 while fixing
the shift. - We briefly disabled bandwidth on the V3c as a workaround on September 27, then re-enabled it.
- We tried a fix that did not work (replaying the whole tuner setup after every change). We measured it,
saw the shift remained and the passband got worse, and dropped it. - The beta7 download was the wrong kind of file (see Before you install).
- A Documentation Truth check failed on our own branch because we moved the driver pin without updating
the three documents that must state it. We only saw it when preparing this release, and fixed it here. - A code review caught a real bug in the driver (a bandwidth list read past its end on CB with the direct
route). It is fixed inesp_rtl_sdr v0.9.1, which this release pins. - Several other real bugs were found and fixed on the way: the reboot when a dongle dropped out during
setup, the silent screen after a hotplug, dashboards that trapped you with no dongle, touches retuning FM on
an unsupported band, and the codec hiss. Each is listed under What is new.
Known issues
We would rather you read this than find out:
Open issues
- #117 an M5Burner install resets all saved settings (Wi-Fi, location, rotation, preferences).
- #116 seven code-review findings not yet triaged, including an AM direct-tune keypad value that can wrap into a wrong frequency if a very large number is typed, and RF Lab bias-T ordering when an enable request is still pending.
- #109 hot-plugging a Blog V3 can knock out the C6
Wi-Fi link (V4 and V4L do not). - #110 one kind of C6 link failure is not detected, so
Wi-Fi never recovers. - #111 about 1.1 MB less free memory after repeated C6
link recoveries. - #78 LoRa never decodes anything (reported on a
specific setup; not yet reproduced or fixed). - #77 Nooelec NESDR SMArt v5 support. Nooelec remains
provisional: it has never worked reliably here. - #72 AM airband reception. Airband is routed to a
generic narrow-FM view and is not proper AM aviation voice. - Driver issues that apply: #32,
#33,
#34,
#35,
#36.
Things we saw and could not explain
- On the test Tab5, FM was once silent at start-up even after unplugging an audio cable, although a built-in
tone played; a reboot fixed it. The cause is not established and it may come back. - On one test the RF Lab LIVE view sounded degraded during FM. It did not recur and is not diagnosed.
- On the V3c, the RDS and pilot readings look lower after a centred retune. Not investigated.
- On the V3c, explicit bandwidth steps read a few dB higher on one side of the spectrum. Not investigated.
- One V3c test run showed a 3.6 dB level difference after returning to AUTO that a repeat did not show.
Not supported or not finished
- 3.20 MS/s WFM audio is unsupported. IQ capture at that rate works; audio does not.
- P25 Phase II voice/audio is not implemented. Shortwave, Airband, Marine and Satellite use generic views and
do not have broad RF acceptance. - The LAN web console has no TLS or authentication: trusted networks only.
- The real widths of the tuner filters in Hz are unmeasured; the numbers are the PC driver's control values.
Troubleshooting
| What you see | What it probably is | What to do |
|---|---|---|
| Black screen after flashing | An incomplete or wrong file | Check the file's SHA-256 and size (3,812,384 bytes), then flash again with M5Burner (#93) |
| Wi-Fi, location or rotation gone after the install | Known: the install resets saved settings (#117) | Enter them again |
| Firmware & Updates shows a C6 version other than 3.0.6 | The C6 has older firmware | Tap UPDATE C6 TO 3.0.6, confirm, and do not power off until it restarts. If the Tab5 cannot reach the C6 at all, that is a manual recovery case: see docs/M5BURNER_RELEASE.md
|
| Wi-Fi stops working after you plug in a V3 | Known: #109 | Restart Wi-Fi from the Wi-Fi screen, or restart the Tab5. V4 and V4L do not do this |
| Wi-Fi does not come back and the screen asks to restart it | The C6 link failed more than three times in a row | Use the restart Wi-Fi option, or restart the Tab5 |
| Dongle not found after a restart | The USB port stayed powered | The firmware power-cycles the port once and retries. If it still fails, unplug and replug the dongle |
| No sound at start-up although a tone plays | Seen once, cause not established | Restart the Tab5, and please tell us if it happens again |
| Spectrum looks shifted or half-missing after NEXT BW | An older build | Upgrade; this is the bug fixed in this release |
| LoRa never decodes | Known: #78 | Not fixed yet |
| Browser has no audio | The web console audio needs its LISTEN HERE control and a trusted network | Open the web console from the same LAN and tap LISTEN HERE |
What we tested, and what we did not
- Tested on real hardware: one M5 Tab5 (ESP32-P4 revision 1.3), an RTL-SDR Blog V3c, V4L and V4. The
tuner-bandwidth cycle above; ten controlled Wi-Fi reboot cycles on the clean production build; DSP A/B on
saved live samples; hotplug swaps. - Automated: the Documentation Truth check, P25 core and radio-scan tests, and the driver's host tests
and compile in its own CI. - Not tested: other Tab5 or display revisions, long soak runs of this exact build, most stations and
bands beyond FM at 96.1 MHz for the bandwidth work, and any Nooelec hardware. - Release-candidate check (2026-09-28, before the package gate): the exact release-candidate app image (driver v0.9.1,
105caa5, app sha256FCD2876A095AEC3E0046AC2175E720BA926440931E18D1A543B5EDEA2D3A3A3C) was flashed over the app partition only and run through the V3c bandwidth cycle at FM 96.1 MHz (AUTO, 200k, 300k, 500k, 1.0M, 1.8M, 2.4M, AUTO, then a retune). The carrier stayed within +1.1 kHz of the requested frequency at every stage; each stage did exactly one tune with the requested width applied; there were no radio restarts, rejected commands, USB overruns or dropped samples or audio. The left side of the spectrum came back after AUTO (-20.5 dB against -20.4 dB at start-up). The whole AUTO passband read 0.3 to 1.8 dB below start-up, a little more than the 0.8 dB seen in earlier runs; the shape is right and the cause of the level difference is not established. The right side again read 2 to 4 dB higher than start-up at explicit widths (known, not investigated). This is one V3c on one Tab5; the V4L and V4 were not re-run on this exact image. - Hardware gate for this package (partly complete): after the M5Burner install the C6 reported
host=3.0.6 coprocessor=3.0.6 match=1with no update offered, and the driver ran as v0.9.1. The install reset the saved settings, so Wi-Fi was set up again by hand. Wi-Fi then connected and stayed connected (saved profile, auto-connect on, 6 access points seen). The FAA aircraft data pack was deleted and downloaded again over Wi-Fi on the installed package and finished, and the catalog reported "Catalog verified" (FAA aircraft, FAA aviation and the Lane County map installed). SD card, re-run on the installed package: the file self-check (create, write, flush, close, read, rename, remove) passed, and a 32 MiB write test ran at 3.8 to 4.4 MiB/s durable across write sizes, all runs passing (SD32G SDHC, 4-bit, 40 MHz). Write speed only; read speed, long recordings and other cards were not measured. V3c tuner-bandwidth cycle on the installed package, twice (AUTO, 200k, 300k, 500k, 1.0M, 1.8M, 2.4M, AUTO, then a retune; FM 96.1 MHz): once after the dongle was hot-swapped in and once after a cold boot with it attached. Both runs kept the carrier within +1.8 kHz at every stage, with exactly one tune per stage, the requested width applied, and no radio restarts, rejected commands, USB overruns or dropped samples or audio. The narrow settings (200k, 300k, 500k) cut the left side of the spectrum by about 19 to 20 dB at the far left, it starts to come back at 1.0M and is back at 1.8M and AUTO; that is the tuner filter and not a shift of the frequency, and it was also watched on the Tab5 screen. After AUTO the left side matched start-up (-22.1 dB against -21.1 dB on the cold boot). The overall AUTO level differed from start-up by 0.3 to 2.1 dB lower on the cold boot and 0.9 to 4.4 dB higher on the hot swap; explicit widths again read 2 to 4 dB higher on the right side (known, not investigated). An earlier attempt was interrupted by a dongle swap after the 300 kHz stage; the swap itself was handled without a reboot. V4L on the installed package, twice. After a hot-swap the carrier stayed within 3 kHz of the requested frequency at every stage (start-up itself was -2.8 kHz), with one tune per stage and no drops, overruns or rejected commands; the narrow widths cut both sides about equally (about -16 to -18 dB at the edges) and AUTO brought every offset back to within 0.7 dB. After a cold boot with the dongle attached (done twice, with a telescopic monopole antenna) the serial checks were clean in the same way and AUTO restored the passband both times. The first cold boot read the carrier at -6.2 kHz at 200k and -7.8 kHz at 300k (start-up -3.4 kHz; 500k to AUTO between -0.4 and -3.5 kHz), larger than any earlier V4L run. The second cold boot did not repeat it: the carrier stayed within 3.7 kHz at every stage (-1.6 kHz at 200k, -2.3 kHz at 300k, start-up -0.5 kHz) and the left side after AUTO matched start-up (-20.7 dB against -21.5 dB). The start-up carrier itself moved by about 3 kHz between the two boots, so a few kHz of run-to-run variation is normal in this measurement. We have not established why the first cold boot read further out (candidates: how the carrier is located when 12 to 19 dB of the passband is cut, station or antenna conditions; none tested). Even the worst value is about 40 times smaller than the original fault (-312 kHz). V4 on the installed package (hot-swapped in, with the dipole antenna and the manual gain at 0.0 dB, which is lower than the 2.7 dB used for the V3c and V4L): the carrier stayed within +1.2 kHz of the requested frequency at every stage (start-up +0.9 kHz), the narrow widths cut only the left side (about -8 dB at the far left, the V4's known shape), and AUTO restored the passband to within 0.2 dB. One failure: at the 1.8M step a tuner register write was rejected by the USB bus (ctrl record rejected ... -> ERROR), the driver rolled back to the previous width, and the width stayed at 1.0M while 1.8M was requested. The bandwidth command only reports that the request was queued (by design), so the failure shows up only as requested (1.8M) not equal to applied (1.0M); our own gate did not check that and marked the stage as passed (a gate gap we will fix). We then repeated the 1.8M step on the same V4 six times: all six applied 1.8M with no rejected write. So the failure was intermittent (1 in 7 steps in that run, 0 in 6 repeats); we have not explained it. It is tracked in #122 and, for the driver, esp-rtl-sdr#38. FM audio by ear, RF24, and the full UI regression on the installed package were not run. These will be run and the results added here.
The full list of changes
Everything since v0.2.0-beta7 (96 commits; the complete list is the
compare view). Pull requests
merged in this window: #99 web audio,
#101 Shortwave and SD speed,
#102 boot and bug-fix batch,
#105 CB scanner,
#107 C6 link recovery,
#113 rc4 driver controls, gain UI and FM fixes,
and #115 the release itself, which also carries the DSP
optimisation work of the closed draft #114.
Radio and dongles
- Pin
esp-rtl-sdrto the tuner-bandwidth fixes, then to the published v0.9.1 release - Use the driver's rc4 controls; label each receiver; keep unsupported bands usable
- Start receiving whenever a dongle is plugged in or swapped; keep dashboards usable with no dongle
- V4 and V4L use the direct HF route on CB; RTL AGC on the V3c's direct-sampling AM path
- Pin the source-backed V3c IF behaviour; restore the V3c's start-up filter state on AUTO
Gain and tuning screens
- Gain control panel on Home; explicit SMART / MANUAL toggle on FM and AM;
RTL_GAINserial command - Larger keypad and keyboard; each band restores its own frequency after a reboot
- FM Listen repaints only what changed; RDS text wraps; the stereo VU is live; the codec idles with no receiver
CB, Shortwave, web console
- Band-wide CB scanner dashboard, and fixes from its review (readable SETUP text, buffers out of internal RAM, spectrum measured only from a CB stream)
- Shortwave: discovery, schedule, hunt, memories, logbook, zoom, pinch, filter edges, CLEAN/BOOST/NR/NOTCH/SQL
- Web console: bounded PCM audio protocol, independent audio per browser, LISTEN HERE, binary spectrum, origin and command validation
Signal processing
- Stage-1 DSP optimisation (batched demodulator state, single-owner resets), bit-identical output on saved samples
- Overload safety valve so a slow DSP no longer trips the watchdog; per-stage timing
- Stage-2 exact-rate frontend lab built, benchmarked and kept out of the shipping firmware (experimental)
Wi-Fi, C6, boot, storage
- C6 link failure detection and recovery; Wi-Fi start at boot and reconnect with back-off
- Fix for the ESP-Hosted use-after-free at start-up; SDIO failure reporting; C6 version read without Wi-Fi
- Embedded splash with staged start-up and USB-A power-cycle recovery; the pinned C6 image embedded in every build
- SD write speed fix (aligned buffers); offline catalog behaviour
Testing and tooling
- Dongle gate in the UI regression script: raw samples at every step, checked against the device's checksum, carrier and passband measured
-SendCommandand-SetSplashGatefor unattended runs; clean-room tools to record and decode the PC driver's USB traffic- Documentation Truth checks kept in step with the driver pin; versioning policy and release procedure written down
Evidence and documents
- Investigation report with logs and plots:
docs/testing/v3c-tuner-bandwidth-transition-2026-09-28.md - Raw-sample checksums and per-run reports:
docs/testing/evidence/v3c-tuner-bandwidth-2026-09-28/ - What is verified and what is not:
PROJECT_STATUS.md - Version numbers and the release procedure:
docs/VERSIONING.md - M5Burner package and the hardware gate:
docs/M5BURNER_RELEASE.md,docs/M5BURNER_HARDWARE_GATE.md - The driver:
esp-rtl-sdr v0.9.1
How to report a problem
Please open an issue at github.com/hardcoreerik/OrcSDR/issues. It helps a lot to include:
- What you did, and what you expected to happen
- Your dongle (V4, V4L, V3c or other) and whether it was plugged in before or after boot
- The version: this is v0.3.0-beta.1 (driver 0.9.1)
- If you can connect the serial port, the output of
RTL_DRIVER STATUSandRTL_HEALTH - A photo of the screen if it is a display problem
How reports are handled is described in
docs/POST_RELEASE_BUG_WORKFLOW.md.
What comes next
- Keep your settings across M5Burner installs (#117): the settings-safe installer avoids it today; fixing M5Burner itself (or updating over Wi-Fi, #119) is next.
- Finish the hardware gate on the installed package (FM audio by ear, RF24 and the full UI regression) and add the results here.
- Triage the code-review findings in #116.
- Find out why one V4L cold boot read -6 to -8 kHz at 200k and 300k when a second did not (recompute the carrier from the raw samples with a second method, and record the antenna for every run), and measure the V4 as it was before the fix.
- Look at the C6 link problems (#109, #110, #111) and the unexplained items listed above.
How this was made
OrcSDR is an open-source hobby project built with extensive AI assistance, outside review and community
testing, as the README says. Every hardware result above was measured on real hardware,
and where we could not measure something we say so.
Thank you
This release exists because people took the time to try the software on their own hardware and tell us
what went wrong. Thank you:
- @unixpunk — seven detailed reports: the installer script with
Windows line endings (#65), the Tab5 only booting over USB-C (#66), maps and data not downloading (#67),
Mute also muting the web UI (#68), choppy web audio (#69), a V3 showing only static (#93) and LoRa never
decoding (#78). Most are fixed, and each one made the product better. He also retested and told us the
beta7 download was wrong. - @Axeman72 — the C6 firmware update problems on beta5 and beta6 (#82).
- @merendaio — the graphical issues (#94).
- @halka — the FM range in Japan (#56).
- @Axpelle — AM airband reception (#72).
- @catalinalb with @fachinformatiker,
@Lunarhop, @mhaberler and
@rogerken1 — the Nooelec v5 thread (#77). - @mihaifireball and @mirrorleos —
asking for RTL-SDR Blog V3 support (#11), and an early attempt at it (#24). - @tekk — the catalog stack-overflow fix (#79).
- @s53zo — the FLARM receiver contribution (#98), which is still open.
- David Coulson (@davidcoulson) — independent Nooelec testing and fixes
in the driver, and careful review of the driver work this release relies on. - The automated reviewers — CodeRabbit (which found the out-of-bounds read described above), GitHub
Copilot and the Codex connector — for catching things a tired human misses. - Everyone who flashed a beta, listened to a station, and wrote back. Please keep telling us what
you hear; seedocs/POST_RELEASE_BUG_WORKFLOW.mdfor how reports are handled.