K-FSW ec10f94
Modular flight software on Zephyr, for small satellites
Loading...
Searching...
No Matches
K-FSW firmware update

Data Structures

struct  kfsw_fwu_status
 

Enumerations

enum  kfsw_fwu_state {
  KFSW_FWU_IDLE = 0 , KFSW_FWU_RECEIVING = 1 , KFSW_FWU_READY = 2 , KFSW_FWU_FAILED = 3 ,
  KFSW_FWU_VERIFIED = 4
}
 

Functions

uint32_t kfsw_fwu_max_image_size (void)
 
uint32_t kfsw_fwu_slot_write_offset (void)
 
int kfsw_fwu_begin (uint32_t total_size, uint32_t expected_crc32)
 
int kfsw_fwu_write (uint32_t offset, const void *data, size_t size)
 
int kfsw_fwu_verify (void)
 
int kfsw_fwu_files_mount (void)
 
int kfsw_fwu_finish (void)
 
int kfsw_fwu_abort (void)
 
int kfsw_fwu_get_status (struct kfsw_fwu_status *status)
 
const char * kfsw_fwu_state_name (enum kfsw_fwu_state state)
 

Description

Receives a firmware image into the secondary image slot and asks the bootloader to try it on the next boot.

Images are written directly to flash. With KFSW_FWU_FILES, both slots are also available as read-only files, without using data filesystem space. The service handles the MCUboot write offset and checks upgrade scheduling.

The CRC32 catches corruption in transit, not tampering. Authenticity is the bootloader's signature check.

Enumeration Documentation

◆ kfsw_fwu_state

#include <fwu.h>

Transfer state.

Enumerator
KFSW_FWU_IDLE 

No transfer in progress.

KFSW_FWU_RECEIVING 

A transfer has begun and is accepting data.

KFSW_FWU_READY 

Fully received, verified, and offered to the bootloader.

KFSW_FWU_FAILED 

The transfer failed; call kfsw_fwu_abort before retrying.

KFSW_FWU_VERIFIED 

Checked and flushed to flash; no upgrade requested yet.

Function Documentation

◆ kfsw_fwu_abort()

int kfsw_fwu_abort ( void  )

#include <fwu.h>

Abandon a transfer and return to idle.

On success the secondary slot is erased. If cleanup fails, the service retains its transfer details in the failed state; call again to retry. Erasing the rollback image during a trial boot is refused.

Return values
0Cleanup completed, or no target partition is bound.
-EBUSYA secondary-slot reader is open.
Returns
A negative errno from flash on cleanup failure.

◆ kfsw_fwu_begin()

int kfsw_fwu_begin ( uint32_t  total_size,
uint32_t  expected_crc32 
)

#include <fwu.h>

Begin receiving an image, erasing whatever the slot held.

Parameters
total_sizeImage size in bytes.
expected_crc32CRC32 (IEEE, as produced by Zephyr's crc32_ieee) over the whole image.
Return values
0The slot is ready to receive.
-ENODEVNo target partition is bound.
-EINVALtotal_size is zero.
-EFBIGtotal_size exceeds kfsw_fwu_max_image_size.
-EBUSYA transfer is receiving, a secondary reader is open, or MCUboot still needs the previous image for trial rollback.
Returns
A negative errno value from the flash layer on failure.

◆ kfsw_fwu_files_mount()

int kfsw_fwu_files_mount ( void  )

#include <fwu.h>

Mount read-only MCUboot images at /kfsw/boot.

firmware_1.bin reads slot0; firmware_2.bin reads slot1. Files contain the image header, payload, and TLVs, excluding slot padding and swap metadata. A secondary reader blocks erase and upgrade requests until it closes. Image visibility checks structure, not the bootloader's signature policy. Call once during service startup, before exposing file transfers.

Returns
0 on success, or a negative errno on failure.

◆ kfsw_fwu_finish()

int kfsw_fwu_finish ( void  )

#include <fwu.h>

Verify the received image and offer it to the bootloader.

On success the image is marked to be tried once. It becomes permanent only if it confirms itself after booting; otherwise the bootloader restores the previous image.

Return values
0The image was accepted and a swap is scheduled.
-EINVALNo transfer is receiving or verified.
-EBUSYA secondary-slot reader is open.
-EAGAINFewer bytes were received than declared.
-EILSEQThe CRC32 does not match what the sender declared.
-EIOThe bootloader did not schedule a swap despite being asked.
Returns
A negative errno value from the flash layer on failure.

◆ kfsw_fwu_get_status()

int kfsw_fwu_get_status ( struct kfsw_fwu_status *  status)

#include <fwu.h>

Read a consistent snapshot of the update state.

Parameters
[out]statusDestination snapshot.
Return values
0The snapshot was written.
-EINVALstatus is NULL.

◆ kfsw_fwu_max_image_size()

uint32_t kfsw_fwu_max_image_size ( void  )

#include <fwu.h>

Largest image the target slot can hold, in bytes.

Smaller than the partition: the swap offset costs one sector at the start, and the bootloader needs its trailer at the end.

Returns
The maximum image size, or zero when no target is bound.

◆ kfsw_fwu_slot_write_offset()

uint32_t kfsw_fwu_slot_write_offset ( void  )

#include <fwu.h>

Byte offset within the target partition where an image is written.

Non-zero because of the bootloader's swap mode.

Returns
The offset in bytes.

◆ kfsw_fwu_state_name()

const char * kfsw_fwu_state_name ( enum kfsw_fwu_state  state)

#include <fwu.h>

Human-readable name for a state, for shells and logs.

Parameters
stateOne of kfsw_fwu_state.
Returns
A stable lowercase name; "unknown" for an unrecognised value.

◆ kfsw_fwu_verify()

int kfsw_fwu_verify ( void  )

#include <fwu.h>

Check the transfer CRC and flush all received bytes to flash.

Does not schedule a boot. Repeated verification of a verified transfer succeeds. Further writes are rejected until a new transfer begins.

Return values
0The complete image is available in flash.
-EINVALNo transfer is receiving or verified.
-EAGAINThe transfer is incomplete.
-EILSEQThe transfer CRC does not match.
Returns
A negative errno from flash on failure.

◆ kfsw_fwu_write()

int kfsw_fwu_write ( uint32_t  offset,
const void *  data,
size_t  size 
)

#include <fwu.h>

Accept the next span of image bytes.

Spans must arrive in order and without gaps.

Parameters
offsetOffset of this span within the image, from zero.
dataBytes to write.
sizeNumber of bytes.
Return values
0The span was accepted.
-EINVALdata is NULL, size is zero, or no transfer is running.
-ESPIPEoffset is not where the transfer had reached.
-EFBIGThe span would run past the declared image size.
Returns
A negative errno value from the flash layer on failure.