|
K-FSW ec10f94
Modular flight software on Zephyr, for small satellites
|
Upload a signed image, reboot into it, then confirm it after checking the node. MCUboot restores the previous image if the trial is unconfirmed at the next reset. The watchdog causes that reset only when it is configured and health monitoring stops feeding it.
With CONFIG_KFSW_FWU_FILES, FTP exposes both flash slots:
| FTP path | Contents |
|---|---|
/boot/firmware_1.bin | Primary slot (slot0): the running image |
/boot/firmware_2.bin | Secondary slot (slot1): the uploaded or previous image |
On the NUCLEO swap profile, MCUboot moves the candidate into the primary slot. The previous image remains in the secondary slot until the next upload or fwu abort erases it. These names identify slots, not firmware versions.
The files read flash directly; they use no space in the board's LittleFS partition. They contain the MCUboot header, payload and TLVs, without slot padding or swap metadata. The local mount is /kfsw/boot.
Both files are read-only. A secondary-slot reader blocks upload, abort and swap requests until it closes. An incomplete or failed upload is unavailable. A readable image has passed structural checks; MCUboot checks its signature before booting it.
Place zephyr.signed.bin in the sending node's filesystem, then run:
/firmware.bin is the reserved upload path (CONFIG_KFSW_FTP_FIRMWARE_PATH). It writes the secondary slot directly. FTP paths such as /build/zephyr.signed.bin are relative to /kfsw/ftp on the sending node; they are not paths on its Linux host.
Successful completion checks the IEEE CRC32, flushes the image to flash and schedules a trial boot. Read it back through /boot/firmware_2.bin before resetting the board.
FWU lite accepts a node file, or a host file on builds with CONFIG_KFSW_FWU_LITE_HOST_FILES. Use an absolute host path outside /kfsw/:
fwu send checks and flushes the image without scheduling a boot. The receiver reports verified. fwu flash schedules the trial and changes it to ready. Both upload paths leave the same slot file available for readback.
Blocks carry an IEEE CRC32. Lost replies are retried; all blocks except the last must have the configured size. Both ends need the same CONFIG_KFSW_FWU_LITE_BLOCK_SIZE. RDP is optional and off by default.
On the flight console:
Check the running version over the link with csp ident 2. A completed upload does not prove that the candidate booted. Check node health and read back the previous image before accepting the candidate:
To revert, reset without confirming. Upload and abort requests return busy while MCUboot needs the secondary image for trial rollback.
Combine the MCUboot, update and CAN profiles for the NUCLEO. FWU lite is optional. Use the same signing key as the installed bootloader.
The host adapter and flight node use 500 kbit/s. See tests/hil/fwu/README.md for upload, readback, revert and confirmation tests. The radio uses the same services; match the UART baud rate at each radio end. When radio encryption is enabled, establish both sessions with uhf connect before uploading. See CSP and links for key setup. Firmware signatures and radio keys serve separate purposes; keep separate keys for them.
| Result | Action |
|---|---|
busy | Wait for the current upload or slot reader to finish |
-EFBIG | Check max_image_bytes in fwu status |
-ESPIPE | Send the next expected offset |
-EAGAIN | Finish sending the declared image size |
-EILSEQ | Check the whole-image IEEE CRC32 |
-EIO when scheduling | Check MCUboot configuration and the write offset |
fwu abort fails | Read the flash error and retry cleanup; the slot may still contain bytes |
fwu abort erases the secondary slot, including any previous image kept there. A failed erase leaves the service in failed with its transfer details intact.
tests/hil/mcuboot/rollback.sh: bootloader revert and wrong-key tests.