Skip to content

Loading and updating a firmware ​

A CanCan is updated over the boat's CAN bus, from the Brain, without opening anything and without a programmer.

Which image goes in which box ​

Released images are named after what they are:

010010005-app_scheiber-firmware.srec     CanCan v1
010010005-V2-app_scheiber-firmware.srec  CanCan v2
PartMeaning
010010005the product ID — the application
-V2present only for CanCan v2 hardware
-firmwarethe update image, loaded over the bus

Three things must line up, and only the first two are checked for you:

  1. The signature. v1 and v2 images are signed with different keys. A box refuses an image signed for the other generation, before writing anything. This is also why a 5.x image never installs on a box running 6.x, and the reverse.
  2. The product ID. Both the box and the image carry one. They must be the same, or you are changing what the box does.
  3. The equipment on CAN 2 must actually match the application. Nothing checks this. A Scheiber gateway happily runs an NMEA 2000 firmware and then understands nothing of what is on its bus.

Read what a box currently is before touching it:

sh
muxen-uds -i can0 -d <address> readconfig --only-name ProductId \
                                          --only-name HardwareId \
                                          --only-name SoftwareVersion

<address> is the device address on the bus — see Reference for how it is formed.

Doing the update ​

sh
muxen-uds -i can0 listfirmware                       # what the Brain has
muxen-uds -i can0 -d <address> firmware --name 010010005-V2-app_scheiber-firmware.srec

While it runs the box is out of service: it stops translating, and the equipment behind it disappears from the boat's screens. Expect that, and do not do it under way. The full command reference lives in the muxen-uds manual, chapter Firmware.

Why a failed update cannot brick a box ​

The box holds two firmware slots. An upload writes the spare slot, never the running one. Only when the whole image has arrived and its signature checks out does the bootloader swap the two and start the new firmware.

The new firmware then has to confirm itself: it marks itself good as soon as it has started properly. If it does not — because it crashes, or because it is not the right image for that hardware — the next reset brings the previous firmware back. A cable pulled mid-upload, a Brain that reboots, a bad image: in every case the box ends up either on the new firmware or on the old one, never on nothing.

The visible symptom of a firmware that cannot confirm itself is the system LED flashing very fast (about 25 times a second) and no traffic on the MUXEN bus. Power-cycle the box: it comes back on the previous version. Then check the image before trying again.

Integration of multiplexed solutions
MUXEN and the MUXEN logo are trademarks of MUXEN SAS.