Skip to content

OpenWrt Image Inspection

HackingGate edited this page Jun 13, 2026 · 3 revisions

OpenWrt Image Inspection

This page documents how to inspect a full Photonicat 2 OpenWrt image without booting it or changing device state.

pcat-manager-web is now open source — the MCU endpoints, socket commands, and update flow previously extracted from bytecode are visible in the source tree.

Download And Verify The Image

Use the official image directory to discover the current image filename and checksum:

BASE_URL=https://dl.photonicat.com/images/photonicat2/openwrt
curl -fL -o /tmp/latest_image.txt "$BASE_URL/latest_image.txt"
IMAGE=$(cat /tmp/latest_image.txt)

cd /tmp
curl -fL -O "$BASE_URL/$IMAGE"
curl -fL -O "$BASE_URL/$IMAGE.sha256"
sha256sum -c "$IMAGE.sha256"

Locate The Root Filesystem

Decompress the image and inspect its partitions:

gzip -cd "/tmp/$IMAGE" > /tmp/photonicat2-openwrt.img
partx -o NR,START,SECTORS,SIZE,TYPE,NAME -g /tmp/photonicat2-openwrt.img

In the inspected Photonicat 2 image, partition 2 was the SquashFS root filesystem. Mount the root filesystem read-only using the partition start sector multiplied by 512 as the byte offset:

START=$(partx -g -o NR,START /tmp/photonicat2-openwrt.img | awk '$1 == 2 { print $2 }')
OFFSET=$((START * 512))

mkdir -p /tmp/photonicat-openwrt-root
sudo mount -t squashfs -o loop,ro,offset="$OFFSET" \
  /tmp/photonicat2-openwrt.img /tmp/photonicat-openwrt-root

Unmount when inspection is complete:

sudo umount /tmp/photonicat-openwrt-root

Inspect Shipped Photonicat Packages

Check the installed package metadata:

sed -n '1,80p' /tmp/photonicat-openwrt-root/usr/lib/opkg/info/pcat-manager-web.control
sed -n '1,80p' /tmp/photonicat-openwrt-root/usr/lib/opkg/info/pcat-manager.control
sed -n '1,200p' /tmp/photonicat-openwrt-root/usr/lib/opkg/info/pcat-manager-web.list
sed -n '1,120p' /tmp/photonicat-openwrt-root/usr/lib/opkg/info/pcat-manager.list

The inspected full image shipped these relevant components:

  • pcat-manager-web 2.2.1-116
  • pcat-manager 2.0.0-45
  • /usr/bin/pcat-pmu-updater

The public package manifest inspected on the IPK workflow page listed pcat-manager-web_2.0.1-27_aarch64_generic.ipk; this page uses the full image because it shipped pcat-manager-web 2.2.1-116.

Inspect Web And PMU Paths

For the web app, prefer reading the source at github.com/photonicat/pcat-manager-web (app/pcat_manager_web.py for MCU endpoints, app/pc_socket_client.py for socket commands).

Search the shipped binaries for PMU/MCU paths:

strings /tmp/photonicat-openwrt-root/usr/bin/pcat-manager |
  rg -i 'pmu|fw-version|socket|pcat-pm-ctl'

strings /tmp/photonicat-openwrt-root/usr/bin/pcat-pmu-updater |
  rg -i 'ARBDPHC2|RA2E1|pmu-fw-version|force|pcat-pm-ctl'

The shipped pcat-pmu-updater strings confirm the same wrapper and runtime requirements as the upstream source: ARBDPHC2, RA2E1, /dev/pcat-pm-ctl, pmu-fw-version-get, and force.

Reverse-Engineer The MCU Web Flow

The web app's MCU update flow is visible in the source:

Source file MCU-related content
app/pcat_manager_web.py mcu_prod_check, mcu_update_start, mcu_dev_check — manifest fetch, firmware download, updater invocation
app/pc_socket_client.py pmu-fw-version-get, query_stm32_version — socket commands for PMU/MCU version queries
app/pcat_config.py MCU manifest URL (latest_img.json) and base URL configuration

The browser-facing endpoints:

/api/v1/mcu_dev_check.json
/api/v1/mcu_prod_check.json
/api/v1/mcu_update.json
/api/v1/mcu_update_status.json

For an MCU update, the frontend posts firmware_url and sha256 to /api/v1/mcu_update.json.

The inspected image shows:

  • The browser calls /api/v1/mcu_dev_check.json, /api/v1/mcu_prod_check.json, /api/v1/mcu_update.json, and /api/v1/mcu_update_status.json.
  • pcat_manager_web.py fetches https://dl.photonicat.com/firmware/pcat2_mcu/latest_img.json for the production MCU check.
  • Relative manifest url values are prefixed with https://dl.photonicat.com/firmware/pcat2_mcu/.
  • The update backend downloads the selected firmware URL, optionally verifies a posted SHA256 value, and runs /usr/bin/pcat-pmu-updater <firmware-path>.
  • -F is appended only for development URLs containing 192.168.8.28, localhost, or 127.0.0.1.

Use pcat-manager-web IPK Inspection for package-level unpacking, and MCU Version Check for the vendor web version and remote manifest flow.

Clone this wiki locally