Appearance
Updating from the HMI
This is the normal route: the Brain has an internet link, the update is assigned to it on the MUXEN update server, and the whole thing is driven from the update page on the screen.
Four steps, and only the second one is a decision:
- Check — ask the update server whether a new version is assigned to this Brain. Nothing on the boat changes.
- Apply — confirm. From here the new version is written into the spare copy of the system software. The Brain keeps running normally throughout.
- Reboot — a few seconds after the install finishes, the Brain restarts into the new copy. This is the only moment the boat loses its screens.
- Confirm — once the new copy has booted and proved itself, the Brain reports the result to the update server by itself. If it did not come up, the bootloader has already put the old copy back, and the Brain reports the failure instead.
Before you start
- Pick your moment. The install is not the disruptive part — the reboot is. Plan for the Brain to be unavailable for a boot cycle, and for a second one if the new version has to be rolled back.
- Check the link. A check is a real round-trip to the update server and needs the boat to be online. On a weak cellular or satellite link it can take the best part of a minute.
- Nothing is lost if you stop. Up to the moment the install finishes, abandoning the update costs nothing but the transfer.
Check
Open the update page and press Check.
The page then shows either that the Brain is up to date, or the version that is waiting, its size, and an action number — the update server's identifier for this particular assignment to this particular Brain. It is worth noting down: it is the one reference that ties what you did on the boat to what the server recorded.
A check changes nothing on the Brain and installs nothing. It is safe to run under way, at any time, as often as you like.
Apply
Press Apply and confirm.
The page then follows the install with a percentage and the name of the step it is on. What is happening underneath is that the new version is being streamed from the update server straight into the copy of the system software the Brain is not running from. There is never a second copy of the image taking up room on the Brain.
While that runs, the boat is unaffected: screens, instruments, CAN bus and every MUXEN service keep working from the copy they booted from.
The Brain reboots about five seconds after the install finishes. Pressing Apply is scheduling a reboot, not starting a download.
What the page shows
| State | Meaning |
|---|---|
idle | nothing offered, nothing running |
available | the last check found an update that has not been applied |
installing | the new version is being written; the percentage and message come from the part of the system doing the writing |
done | installed; the reboot is a few seconds away |
failed | the install failed, or the Brain came back on the old version |
Alongside it the page shows the installed version — the version of the copy the Brain actually booted from — and the last result of the previous update, success or failure, which survives reboots.
Expect the page to lose contact with the Brain while it reboots. That is the successful path, not an error. Reload it once the Brain is back.
After the reboot
The Brain finishes the job on its own. It checks that it came back on the version it installed and that the system reported itself healthy, then tells the update server the outcome. Nothing on the screen has to be pressed for that to happen.
Two consequences worth knowing:
- A failure stays retryable. An update that failed is not marked as applied, so the same version is offered again at the next check and can be applied again once the cause is fixed.
- Between the reboot and the confirmation, the update page reports no update available. That is correct, not a fault: the Brain is not going to offer you again the version it has just installed and is still confirming. If the boat has no link at that moment, the Brain keeps the result and reports it as soon as it has one.
Check the installed version on the page after the reboot. If it is the new one, the update is done.
From a shell
The same three operations exist as commands on the Brain — muxen-rauc-client check, apply and status — and talk to the same service the page does, so a shell and a screen always see the same state. That route is a MUXEN-engineering one and is documented in internal/update-flow.md.
