Skip to content

Flash MCU Firmware

HackingGate edited this page Aug 14, 2026 · 6 revisions

Flash MCU Firmware

This page documents the MCU firmware flash procedure. Do not start here until pcat-pmu-updater is installed and the firmware package has been downloaded and validated.

Safety Checklist

  • Stable AC power is connected.
  • The firmware package validates as ARBDPHC2 and RA2E1.
  • The target version is intentional.
  • /dev/pcat-pm-ctl exists.
  • pcat-pmu-updater --pmu-fw-version-get queries the current firmware successfully with the installed driver/updater pair.
  • No one will unplug power or reboot during the update.

Query Current Version

sudo pcat-pmu-updater --pmu-fw-version-get

Also record the kernel driver's view:

cat /sys/kernel/photonicat-pm/pmu_hw_version
cat /sys/kernel/photonicat-pm/pmu_fw_version

Flash A Newer Firmware

sudo pcat-pmu-updater /tmp/pcat2-firmware.bin

Downgrade Or Reinstall The Same Version

The updater refuses older or same-version firmware by default. Use --force only when intentionally downgrading or reinstalling:

sudo pcat-pmu-updater --force /tmp/pcat2-firmware.bin

Flash An Older MCU Version

Pick an older package from the versions.json index described in Check and Download MCU Firmware. Do not use ota.bin for this: it tracks the current production manifest target, not a previous version.

curl -fL -o /tmp/pcat2-mcu-older.bin \
  https://dl.photonicat.com/firmware/pcat2_mcu/ota_RA2E120260702104522.bin

Validate the downloaded file first. When the image is older than the running MCU version, flashing it is a downgrade:

sudo pcat-pmu-updater --force /tmp/pcat2-mcu-older.bin

Use the installed updater path on the target system. Vendor OpenWrt images may use /usr/bin/pcat-pmu-updater; local source builds are often installed as /usr/local/sbin/pcat-pmu-updater.

If the upstream updater's --pmu-fw-version-get command hangs, do not bypass the check by modifying or wrapping pcat-pmu-updater. The updater owns the MCU update sequence and must be able to receive PMU replies through /dev/pcat-pm-ctl before flashing. Use sysfs only to record the current driver view while diagnosing the raw control path:

cat /sys/kernel/photonicat-pm/pmu_fw_version

Do not continue to flashing until the installed driver/updater combination can run pcat-pmu-updater --pmu-fw-version-get successfully. For this driver repository, a hang here should be treated as a driver raw-control forwarding issue, not as a reason to patch the updater.

After a successful flash, the updater prints success and powers off the system. Wait for shutdown to complete, then restore power and boot again.

Verify After Boot

A successful updater run is not proof that the firmware was applied. Some vendor releases stream to 100%, print PMU firmware updated successfully., and then roll back: the PMU comes up on a different, older version. Always re-read the version after the board boots.

cat /sys/kernel/photonicat-pm/pmu_fw_version

When the installed driver forwards PMU version acknowledgements to /dev/pcat-pm-ctl, also verify through the updater:

sudo pcat-pmu-updater --pmu-fw-version-get

Updater Protocol Reference

The upstream updater source validates the wrapper and CRC, stops /etc/init.d/pcat-manager if present, opens /dev/pcat-pm-ctl, queries firmware version with PMU command 0x05, and then sends the update sequence with commands 0xCB, 0xCD, 0xD3, and 0xCF.

During that sequence it waits for PMU status or acknowledgement commands 0xC9, 0xD5, 0xD4, and 0xD0. Firmware data is streamed in chunks up to 256 bytes. After a successful finish acknowledgement, the updater powers off the system so the PMU applies the new firmware.

The 30-byte firmware info payload used by the upstream updater is:

bytes 0..12:   ASCII "2025010100cat"
bytes 13..24:  raw firmware size as a zero-padded 12-digit decimal string
bytes 25..29:  ASCII "00000"

Common Failure Points

  • This device is not compatible for PMU firmware update!: /proc/device-tree/compatible did not contain ariaboard,photonicat2.
  • Failed to open firmware file: the path is wrong or not readable.
  • Invalid file header: the file is not a wrapped Photonicat MCU package.
  • Invalid version: the version string does not start with RA2E1.
  • checksum error: the file is corrupt or not a valid package.
  • Failure opening /dev/pcat-pm-ctl: the loaded driver does not expose the raw PMU control device.
  • pcat-pmu-updater --pmu-fw-version-get hangs: the updater opened /dev/pcat-pm-ctl, but the driver/updater pair did not deliver a PMU reply back to userspace. Do not flash until the raw control path is fixed.
  • The flash reports success but the version does not change: the MCU rolled the update back. RA2E1260730001 and RA2E1260813002 both do this, and both land on RA2E1250815002 regardless of the version that was running before. This is MCU-side behavior, not a control-path fault. See Recent MCU Firmware Does Not Persist.

Clone this wiki locally