DFU for external BLE Sensor

Hi,

  I have a current project that is based on the nRf52840.  This project acts both as a peripheral and a central.  I have a need to update the firmware on a remote BLE sensor using DFU, i.e., I need to do exactly what the nRfConnect application does when it updates a peripheral firmware via DFU.  My thought was to use the nRf52840 dongle and develop this code on my PC and then port it to my embedded system.  I also thought the best starting point would be the source code for the nRfConnect application which I would port it but I see from user comments that nordic did not release the source code for this.  Is it possible to get this source code or is there another example that demonstrates what I need to accomplish?

Thanks!

Parents
  • Hi,

      I am a bit confused and am hoping that you can help.  I have a Laird BT610 sensor and when I connect to it it does not show a Secure DFU service; however, I can do an over the air update of this sensor using nRfConnect and a proper firmware.bin file for this sensor. The sensor does advertise the SMP Serviice.  Is nRfConnect using this service to perform the firmware update?

    Thanks,

    Dave

  • Hi Dave,

    I am sorry for the confusion. I assumed your FW was based on our nRF5 SDK which uses a different DFU protocol.  So my initial reply does not apply to your case. As you may know, the nRF connect SDK is relying on the DFU protocol from MCUmgr for FW updates over BLE.

    Here are the MCUmgr libraries we use for our ios and android apps:

    https://github.com/NordicSemiconductor/Android-nRF-Connect-Device-Manager

    https://github.com/NordicSemiconductor/IOS-nRF-Connect-Device-Manager

    Best regards,

    Vidar

  • Excellent! I did not even think of using debug logs from the phone. My plan was to try to log the data from the DFU target. I didn't get that far though. Not sure if I would have been able to log the data fast enough either.

    I will report the missing documentation as a feature request. Hopefully we can add it so others who are developing their own DFU clients in the future do not have to reverse engineer the protocol like you had to.

    Thanks for the update.

    Vidar

  • Hi,

    There is one piece of information that I have been unable to figure out.  The first block of data in the upload contains the entire image length and a "sha" field.  Below is a real example of the data in both binary and the "json" representation of the cbor data.  I need to know exactly what the "sha" is and how to calculate it so I can include the "sha" with my uploads.

    Binary data = SMPHeader|CBOR_Data packet: 020000f400010001bf646461746158d53db8f3960000000000020000fca5070000000000011b0100860e536100000000ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff636c656e1a0007a8936373686143525249636f666600ff

    SMPHeader: 020000f400010001

    CBOR_Data: bf646461746158d53db8f3960000000000020000fca5070000000000011b0100860e536100000000ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff636c656e1a0007a8936373686143525249636f666600ff

    cbor json: {"data": h'3DB8F3960000000000020000FCA5070000000000011B0100860E536100000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF', "len": 501907, "sha": h'525249', "off": 0}

    Thanks,

    Dave Patton

  • Hi Dave,

    It's the sha-256 digest of your signed image, but only the first 3 bytes of it: https://github.com/zephyrproject-rtos/mcumgr/blob/master/cmd/img_mgmt/src/img_mgmt.c#L493-L501

    The easiest way to get the digest (is placed in the image trailer) is to use the imgtool and run imgtool verify <signed_image>

    Best regards,

    Vidar

  • Hi, I am trying to move this code into my non-dev board project and for this file nrf_queue.c this is at the top of the file.

    #if NRF_MODULE_ENABLED(NRF_QUEUE)

    This currently is false so none of the code in this file is active.  I added this to my sdk_config.h

    // <e> NRF_QUEUE_ENABLED - nrf_queue - Queue module
    //==========================================================
    #ifndef NRF_QUEUE_ENABLED
    #define NRF_QUEUE_ENABLED 1
    #endif
    // <q> NRF_QUEUE_CLI_CMDS - Enable CLI commands specific to the module

    however, that did not enable the code in nrf_queue.c.  How can I enable this code?

    Thanks

    Dave

  • Hi Dave,

    Are you sure you need to create a new project for this? Normally it's sufficient to just change the board file (Using the SDK with other boards) in addition to maybe updating some of the global pre-processor defines. Anyway. The code in nrf_queue.c should become enabled as long as NRF_QUEUE_ENABLED==1. Maybe it's being defined as '0' elsewhere in your project?

    Vidar

Reply Children
  • Hi,

      I did the DFU via SMP project on the Dev kit to get it working.  I now have to move that code to our real project that has many other things in it.  Unfortunately our project was based on an SDK that did not contain the BLE GATT QUEUE.  I copied the /ble/nrf_ble_gq directory from the 17.01 SDK to our project to add the BLE GAT QUEUE.  Then I added the following to the skd_config.h file:

    // <e> NRF_QUEUE_ENABLED - nrf_queue - Queue module
    //==========================================================
    #ifndef NRF_QUEUE_ENABLED
    #define NRF_QUEUE_ENABLED 1
    #endif

    // <o> NRF_BLE_GQ_BLE_OBSERVER_PRIO
    // <i> Priority with which BLE events are dispatched to the GATT Queue module.

    #ifndef NRF_BLE_GQ_BLE_OBSERVER_PRIO
    #define NRF_BLE_GQ_BLE_OBSERVER_PRIO 1
    #endif

    // <e> NRF_BLE_GQ_ENABLED - nrf_ble_gq - BLE GATT Queue Module
    //==========================================================
    #ifndef NRF_BLE_GQ_ENABLED
    #define NRF_BLE_GQ_ENABLED 1
    #endif
    // <o> NRF_BLE_GQ_DATAPOOL_ELEMENT_SIZE - Default size of a single element in the pool of memory objects.
    #ifndef NRF_BLE_GQ_DATAPOOL_ELEMENT_SIZE
    #define NRF_BLE_GQ_DATAPOOL_ELEMENT_SIZE 20
    #endif

    // <o> NRF_BLE_GQ_DATAPOOL_ELEMENT_COUNT - Default number of elements in the pool of memory objects.
    #ifndef NRF_BLE_GQ_DATAPOOL_ELEMENT_COUNT
    #define NRF_BLE_GQ_DATAPOOL_ELEMENT_COUNT 8
    #endif

    // <o> NRF_BLE_GQ_GATTC_WRITE_MAX_DATA_LEN - Maximal size of the data inside GATTC write request (in bytes).
    #ifndef NRF_BLE_GQ_GATTC_WRITE_MAX_DATA_LEN
    #define NRF_BLE_GQ_GATTC_WRITE_MAX_DATA_LEN 2
    #endif

    // <o> NRF_BLE_GQ_GATTS_HVX_MAX_DATA_LEN - Maximal size of the data inside GATTC notification or indication request (in bytes).
    #ifndef NRF_BLE_GQ_GATTS_HVX_MAX_DATA_LEN
    #define NRF_BLE_GQ_GATTS_HVX_MAX_DATA_LEN 16
    #endif

    To me this looks like all that should be required but I am getting a compile error that I can't figure out.  I tried searching online for others having this issue but I have been unable to find anything, can you help with this.  The code that is generating the error is:

    NRF_BLE_GQ_DEF(m_ble_gatt_queue, /**< BLE GATT Queue instance. */
    NRF_SDH_BLE_CENTRAL_LINK_COUNT,
    NRF_BLE_GQ_QUEUE_SIZE);

    Building ‘SkyHub’ from solution ‘Solution ‘SkyHub’’ in configuration ‘Release’
    Preprocessing file_transfer.c
    Preprocessing packet_processing.c
    Preprocessing pc_uart_interface.c
    Preprocessing mobile_app_interface.c
    Preprocessing sky_dfu.c
    Preprocessing skybitz_app.c
    Preprocessing int_flash.c
    Preprocessing mx25flash_spi.c
    Preprocessing spi_flash.c
    Preprocessing skycam_ota.c
    Preprocessing con_controller.c
    Compiling ‘file_transfer.c’
    Compiling ‘packet_processing.c’
    Compiling ‘pc_uart_interface.c’
    Preprocessing rtc_timer.c
    Compiling ‘mobile_app_interface.c’
    Compiling ‘sky_dfu.c’
    Compiling ‘mx25flash_spi.c’
    Compiling ‘int_flash.c’
    Compiling ‘skybitz_app.c’
    unknown type name 'm_ble_gatt_queuereq_queue'
    expected declaration specifiers or '...' before numeric constant
    expected declaration specifiers or '...' before 'NRF_QUEUE_MODE_NO_OVERFLOW'
    expected declaration specifiers or '...' before numeric constant
    'm_ble_gatt_queuereq_queue' undeclared here (not in a function); did you mean 'm_ble_gatt_queuepurge_queue'?
    conversion from 'unsigned int' to 'unsigned char' changes value from '4022250974' to '222' [-Woverflow]
    Compiling ‘spi_flash.c’
    Compiling ‘skycam_ota.c’
    Compiling ‘con_controller.c’
    Compiling ‘rtc_timer.c’
    Build failed
     

    Thanks,

    Dave Patton

  • Hi,

      I forgot to mention that the file that gets the compile error contains these header includes>

    #include "../../nRF_Includes/queue/nrf_queue.h"
    #include "../../nRF_Includes/nrf_ble_gq/nrf_ble_gq.h"

    I would have expected these headers to resolve the compile issues but they did not.

  • Nevermind, I solved it.  My project has a queue dir that contained the QUEUE files nrf_queue.h and nrf_queue.c from the earlier SDK.  I copied those files from the 17.1SDK and the code now builds.

    Thanks,

    Dave

  • Hi,

    I am having 2 very weird problems, one seems like it may be compiler related.  The other one I am clueless about.  I will explain both below.

    *************************    PROBLEM #1    ********************************

    See the code below:

    BLE_NUS_C_DEF(m_ble_nus_c);
    
    uint32_t ble_nus_c_init(ble_nus_c_t * p_ble_nus_c, ble_nus_c_init_t * p_ble_nus_c_init)
    {
        uint32_t      err_code;
        ble_uuid_t    uart_uuid;
        ble_uuid128_t nus_base_uuid = NUS_BASE_UUID;
    
        VERIFY_PARAM_NOT_NULL(p_ble_nus_c);
        VERIFY_PARAM_NOT_NULL(p_ble_nus_c_init);
    
        err_code = sd_ble_uuid_vs_add(&nus_base_uuid, &p_ble_nus_c->uuid_type);
        VERIFY_SUCCESS(err_code);
    
        uart_uuid.type = p_ble_nus_c->uuid_type;
        uart_uuid.uuid = BLE_UUID_NUS_SERVICE;
    
        p_ble_nus_c->conn_handle           = (uint16_t)0x1111;
        p_ble_nus_c->conn_handle           = BLE_CONN_HANDLE_INVALID;
        p_ble_nus_c->evt_handler           = p_ble_nus_c_init->evt_handler;
        p_ble_nus_c->handles.nus_tx_handle = (uint16_t)0x2222;
        p_ble_nus_c->handles.nus_tx_handle = BLE_GATT_HANDLE_INVALID;
        p_ble_nus_c->handles.nus_status_handle = BLE_GATT_HANDLE_INVALID;
        p_ble_nus_c->handles.nus_buffer_handle = BLE_GATT_HANDLE_INVALID;
        p_ble_nus_c->handles.nus_rx_handle = BLE_GATT_HANDLE_INVALID;
    
    	print_trace("ble_nus_c_init(1) p_ble_nus_c->conn_handle: %d", p_ble_nus_c->conn_handle);
        err_code = ble_db_discovery_evt_register(&uart_uuid);
    	print_trace("ble_nus_c_init(2) p_ble_nus_c->conn_handle: %d", p_ble_nus_c->conn_handle);
    
    	return err_code;
    }
    
    /**@brief Function for initializing the Nordic UART Service (NUS) client. */
    static void nus_c_init(void)//FA191118
    {
    	ret_code_t  err_code;
    	ble_nus_c_init_t init;
    
    	init.evt_handler = ble_nus_c_evt_handler;
    
    	err_code = ble_nus_c_init(&m_ble_nus_c, &init);
    	APP_ERROR_CHECK(err_code);
    }
    
    void main(void)
    {
        nus_c_init();
    }

    What is happening is that when I run this line of code:  p_ble_nus_c->conn_handle = (uint16_t)0x1111; it does not set the conn_handle to 0x1111, it sets it to 0x0011 and also sets part of the nus_tx_handle when this instruction is executed.  I have attached a screen shot of the debugger showing this.

    This started happening after I pulled the SMP implementation from the dev board project to our real project.  Our real project was based on a SDK that did not contain the GAT QUEUE stuff, i.e., nrf_ble_gq.c and nrf_ble_gq.h.  I therefore copied these file from the 17.1SDK into our real project.  I then had to replace the nrf_queue.c and nrf_queue.h in our real project with the files from the 17.1SDK to get the project to build.  The SMP service stuff is now working in our real project.

    *************************    PROBLEM #2    ********************************

    I can no longer initialize the watchdog.  Here is the code:

    static void watchdog_init(void)
    {
    	uint32_t err_code = NRF_SUCCESS;
    	//Configure WDT.
    	nrf_drv_wdt_config_t config = NRF_DRV_WDT_DEAFULT_CONFIG;
    	err_code = nrf_drv_wdt_init(&config, wdt_event_handler);
    	APP_ERROR_CHECK(err_code);
    	err_code = nrf_drv_wdt_channel_alloc(&m_channel_id);
    	APP_ERROR_CHECK(err_code);
    	nrf_drv_wdt_enable();
    }
    
    int main(void)
    {
        watchdog_init();
    }

    It is crashing inside watchdog_init() at this line:  err_code = nrf_drv_wdt_init(&config, wdt_event_handler);

    Look at this line:  nrf_drv_wdt_config_t config = NRF_DRV_WDT_DEAFULT_CONFIG;

    Below is a Debug Watch showing the values:

    When I single step through the functions I get to the function below

    nrfx_err_t nrfx_wdt_init(nrfx_wdt_config_t const * p_config,
                             nrfx_wdt_event_handler_t  wdt_event_handler)
    {
        NRFX_ASSERT(p_config);
        nrfx_err_t err_code;
    
    #if !NRFX_CHECK(NRFX_WDT_CONFIG_NO_IRQ)
        NRFX_ASSERT(wdt_event_handler != NULL);
        m_wdt_event_handler = wdt_event_handler;
    #else
        NRFX_ASSERT(wdt_event_handler == NULL);
        (void)wdt_event_handler;
    #endif
        if (m_state == NRFX_DRV_STATE_UNINITIALIZED)
        {
            m_state = NRFX_DRV_STATE_INITIALIZED;
        }
        else
        {
            err_code = NRFX_ERROR_INVALID_STATE;
            NRFX_LOG_WARNING("Function: %s, error code: %s.",
                             __func__,
                             NRFX_LOG_ERROR_STRING_GET(err_code));
            return err_code;
        }
    
        nrf_wdt_behaviour_set(p_config->behaviour);
    
        nrf_wdt_reload_value_set((p_config->reload_value * 32768) / 1000);
    
    #if !NRFX_CHECK(NRFX_WDT_CONFIG_NO_IRQ)
        NRFX_IRQ_PRIORITY_SET(WDT_IRQn, p_config->interrupt_priority);
        NRFX_IRQ_ENABLE(WDT_IRQn);
    #endif
    
        err_code = NRFX_SUCCESS;
        NRFX_LOG_INFO("Function: %s, error code: %s.", __func__, NRFX_LOG_ERROR_STRING_GET(err_code));
        return err_code;
    }
    

    I set a breakpoint at this line:  NRFX_IRQ_PRIORITY_SET(WDT_IRQn, p_config->interrupt_priority);

    And then look at the p_config variable which should be filled with NRF_DRV_WDT_DEAFULT_CONFIG but it is not.  I have attached a debug screen showing this below.

    If after entering the nrfx_wdt_init function I stop at a breakpoint and  adjust the p_config  data values to be those of NRF_DRV_WDT_DEAFULT_CONFIG Before NRFX_IRQ_PRIORITY_SET(WDT_IRQn, p_config->interrupt_priority); is called then I do not get a crash.   This is similar to the first problem, the compiler seems like it is messing things up.

    I am guessing that this may have been caused by adding in the SMP stuff to our real project since it did not happen prior to that.  I have been beating my head against a wall all day trying to make sense of this.  I am really hoping that you have some ideas.

    Thanks,

    Dave Patton

  • Hi,

      I am still struggling with the integration of the SMP stuff into our real app, I detailed some issues in the last message.  The funny thing is that the SMP stuff is working in our real app now.  The addition of the SMP stuff into our real app has broken so many things now and I believe it is because our real app is based on an earlier SDK.  Is it possible to implement the SMP stuff in an earlier SDK?

Related