Skip to content

MCU Version Check

HackingGate edited this page Aug 14, 2026 · 6 revisions

MCU Version Check

This page documents how to check the running MCU/PMU firmware version and how the vendor OpenWrt web app checks the remote MCU manifest. It does not flash firmware.

pcat-manager-web is now open source — the socket commands, endpoints, and manifest logic previously recovered from bytecode are visible in the source tree.

Direct Device Checks

With the kernel driver loaded:

cat /sys/kernel/photonicat-pm/pmu_hw_version
cat /sys/kernel/photonicat-pm/pmu_fw_version

With pcat-pmu-updater installed and /dev/pcat-pm-ctl available:

sudo pcat-pmu-updater --pmu-fw-version-get

If this updater command hangs, use the sysfs pmu_fw_version value only to record the driver's current view while diagnosing the raw control path. Do not patch or wrap pcat-pmu-updater to bypass the query. The updater owns the MCU update sequence, and flashing is blocked until /dev/pcat-pm-ctl can deliver PMU replies back to the unmodified updater.

A version string reported by the device identifies the running PMU firmware. It does not prove that a matching downloadable firmware package is installed locally or publicly listed.

Full OpenWrt Image Evidence

The MCU remote-check path was found by inspecting the full Photonicat 2 OpenWrt image.

In the inspected image, package metadata showed:

pcat-manager-web 2.2.1-116
pcat-manager 2.0.0-45
/usr/bin/pcat-pmu-updater

Use OpenWrt Image Inspection to mount the image read-only, then inspect these paths:

/usr/share/pcat-manager-web/pcat_manager_web.pyc
/usr/share/pcat-manager-web/pc_socket_client.pyc
/usr/share/pcat-manager-web/templates/ed1042cf-3b0b-4a51-a222-08af0e0cee67.html
/usr/bin/pcat-manager
/usr/bin/pcat-pmu-updater

The corresponding source is at github.com/photonicat/pcat-manager-web.

Local Version Path

The vendor web app does not query the PMU directly. The inspected image shows this local path:

pcat-manager-web -> /tmp/pcat-manager.sock -> pcat-manager -> /dev/pcat-pm-ctl -> PMU

The web side of this chain is in app/pc_socket_client.py (source):

  • query_stm32_version — requests the local MCU firmware version
  • pmu-fw-version-get — PMU firmware version query

Verify the daemon strings:

strings /tmp/photonicat-openwrt-root/usr/bin/pcat-manager |
  rg -i 'pcat-manager.sock|pmu-fw-version-get|PMU FW Version|pcat-pm-ctl'

The relevant inspected strings were:

stm32_firmware_version
query_stm32_version
/tmp/pcat-manager.sock
pmu-fw-version-get
PMU FW Version: %s
/dev/pcat-pm-ctl

Web Frontend MCU Calls

The update page template contains the browser-side MCU calls — see the source templates at github.com/photonicat/pcat-manager-web:

sed -n '760,1040p' \
  /tmp/photonicat-openwrt-root/usr/share/pcat-manager-web/templates/ed1042cf-3b0b-4a51-a222-08af0e0cee67.html |
  rg -n 'mcu_dev_check|mcu_prod_check|mcu_update|mcu_update_status|firmware_url|sha256'

The inspected template calls:

/api/v1/mcu_dev_check.json
/api/v1/mcu_prod_check.json
/api/v1/mcu_update.json
/api/v1/mcu_update_status.json

For an MCU update, the frontend posts firmware_url and sha256 to /api/v1/mcu_update.json.

Backend Production Check

The production check in app/pcat_manager_web.py (mcu_prod_check function) reads:

https://dl.photonicat.com/firmware/pcat2_mcu/latest_img.json

It parses these JSON keys:

version
url
sha256
build_date

If the manifest url is relative, the backend prefixes it with:

https://dl.photonicat.com/firmware/pcat2_mcu/

The response fields returned to the frontend include:

local_version
prod_version
prod_firmware_url
prod_sha256
prod_build_date
update_available
newer_available
same_version

The public production manifest contains sha256sum; Check and Download MCU Firmware checks sha256sum and sha256.

The backend checks only latest_img.json. The server also publishes an older-version index at https://dl.photonicat.com/firmware/pcat2_mcu/versions.json, but no shipped web build reads it: the pcat-manager-web_2.2.1-146 IPK bytecode references latest_img.json and the dev-server URL only. There is no vendor UI for picking an older MCU version, so use the index manually — see Check and Download MCU Firmware.

Backend Update Path

The mcu_update_start function in app/pcat_manager_web.py shows this update sequence:

  1. Read firmware_url and optional sha256 from the request.
  2. Download the firmware to a temporary mcu_firmware.bin.
  3. Verify SHA256 only when a sha256 value is provided.
  4. Run /usr/bin/pcat-pmu-updater <firmware-path>.
  5. Append -F only when the firmware URL contains 192.168.8.28, localhost, or 127.0.0.1.
  6. Query the local MCU version again through query_stm32_version.

For manual work, prefer the verified workflow: read the manifest, download the referenced file, verify the manifest checksum, validate the ARBDPHC2 wrapper, then flash with pcat-pmu-updater.

Clone this wiki locally