# Writing a custom Mender client for an MCU

**URL:** <https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404>\
**Category:** General Discussions\
**Created:** [November 13, 2022, 8:53pm UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404 "2022-11-13T20:53:23Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 13, 2022, 8:53pm UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/1 "2022-11-13T20:53:23Z")

</div>

Hello @mirzak

Thanks for this tutorial [How to write a custom client interfacing a Mender server](https://hub.mender.io/t/how-to-write-a-custom-client-interfacing-a-mender-server/1353). I’m currently working on an MCU solution to perform OTA using mender.

Several questions please about the download of the artifact, that you don’t really detail here:

- I realize the expire date of the URI to download the artefact is very short, let say about 3 seconds for me!!! Is it wanted ? Configurable ?
- My understanding is that I can do a simple GET with the URI, no need for JWT etc, is it correct ?
- What will be exactly downloaded using this URI ? .mender file uploaded on the server ? Something else ?

Edit: after trying to download, I can answer the two last questions: no need of token the URI serves as an authentication method and mender file is retrieved. So one question comes to me:

- I have retrieved the mender file but it’s not very suitable because I need to access the bin file inside the data\0000.tar.gz archive. So I need to untar twice now. Clearly will need a lot of memory so I’m thinking another solution: is it possible to retrieve the bin file inside data\0000.tar.gz archive directly from mender ? If this is not a functionality you have I’m thinking to create a small docker container that do the job for me on the fly.

Thanks,  
Joel

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 17, 2022, 11:41pm UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/2 "2022-11-17T23:41:51Z")

</div>

Answering some question I ask myself:

- The bucket is managed by minio container on the server side.
- An URL is generated to download the artefact from minio. The format is describe here: [Authenticating Requests: Using Query Parameters (AWS Signature Version 4) - Amazon Simple Storage Service](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-query-string-auth.html)
- It should be possible to download a single file from the artefact (ref: [Small File Archives in MinIO](https://blog.min.io/small-file-archives/)), by appending the path inside the artefact at the end of the UUID of the artefact, for example:

[https://mymender.com/mender-artifact-storage/1d95c890-12d4-442d-8f0f-99bddb38c930?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=mender-deployments0.000000202211170.000000us-east-10.000000s30.000000aws4\_request&X-Amz-Date=20221117T223248Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&response-content-type=application0.000000vnd.mender-artifact&X-Amz-Signature=88e5f3f62ec596b7d47084293a1bf1f62261ef1c01cc00d416ba35e979800439](https://mymender.com/mender-artifact-storage/1d95c890-12d4-442d-8f0f-99bddb38c930?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=mender-deployments0.000000202211170.000000us-east-10.000000s30.000000aws4_request&X-Amz-Date=20221117T223248Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&response-content-type=application0.000000vnd.mender-artifact&X-Amz-Signature=88e5f3f62ec596b7d47084293a1bf1f62261ef1c01cc00d416ba35e979800439)

becomes:

[https://mymender.com/mender-artifact-storage/1d95c890-12d4-442d-8f0f-99bddb38c930/version?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=mender-deployments0.000000202211170.000000us-east-10.000000s30.000000aws4\_request&X-Amz-Date=20221117T223248Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&response-content-type=application0.000000vnd.mender-artifact&X-Amz-Signature=](https://mymender.com/mender-artifact-storage/1d95c890-12d4-442d-8f0f-99bddb38c930/version?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=mender-deployments0.000000202211170.000000us-east-10.000000s30.000000aws4_request&X-Amz-Date=20221117T223248Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&response-content-type=application0.000000vnd.mender-artifact&X-Amz-Signature=)

Up to this point, is there anybody at mender side able to confirm ?

If this is correct now the URL need to have a new X-Amz-Signature because it depends of the GET path, which is not so easy to compute but should be possible. Is it (on the device side) ?

WIP…

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [November 18, 2022, 7:52am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/3 "2022-11-18T07:52:52Z")

</div>

Hello @joelguittet,

By default, the download URL are valid for 900 seconds:

> <https://github.com/mendersoftware/deployments/blob/master/config.yaml#L110>

You don’t need a JWT token, because the download URL is presigned. A GET request is enough to download the artifact, which will be the “.mender” file you uploaded to the server. Once you have the mender file, you need to parse it. We use the [mender-artifact](https://github.com/mendersoftware/mender-artifact) golang library to parse it, but you can do it manually if you are using a different programming language because a mender file is basically a tarball.

You can find the format specification here:

> <https://github.com/mendersoftware/mender-artifact/blob/master/Documentation/artifact-format-v3.md>

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 18, 2022, 8:05am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/4 "2022-11-18T08:05:57Z")

</div>

Hello @tranchitella

Yes I understood that points, parsing the docker configurations and different GO sources (even if it is not my cup of tea!)  
Thanks for the location of the expire delay location.  
My difficulty is the extraction of the mender file because of the limited ressources on the MCU.

Working on a solution that should fit the need on this… 🙂

Will update here depending of my progress.

Joel

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [November 18, 2022, 8:14am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/5 "2022-11-18T08:14:37Z")

</div>

The mender artifact is an uncompressed tarball which you can read as you receive it from the server (stream of bytes). It is designed this way to work on devices with limited (cpu, storage) resources.

Keep us posted!

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [November 18, 2022, 8:17am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/6 "2022-11-18T08:17:07Z")

</div>

Hi @joelguittet

If your problem is memory with the Artifact, it is not necessary to download the whole thing up front, and then parse it.

It is a `tar` format, so it can be handled in a stream. Most `tar` libraries should be able to do this for you.

Are you writing this in C? Which tar lib are you using?

Also, although Artifacts can be compressed (as you have observed), they don’t have to. It is possible to leave the Artifact uncompressed if you want to.

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 19, 2022, 7:23am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/7 "2022-11-19T07:23:40Z")

</div>

Hello,  
Tar library not chosen yet, if you have a good light-weight one to recommend I m open 🙂 yes I m looking for pure C language.  
You indicate it is not mandatory to compress artifacts, can you detail this? Is it an option when creating the mender artifact file?  
Joel

---

<div class="post-metadata">

**Author:** ![dellgreen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/dellgreen/32/85_2.png) [@dellgreen](https://hub.mender.io/u/dellgreen)\
**Post date:** [November 19, 2022, 1:25pm UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/8 "2022-11-19T13:25:46Z")

</div>

Information on configuring compression for mender artifact creation can be found here

> <https://github.com/mendersoftware/mender-convert/blob/master/configs/mender_convert_config#L25>

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 20, 2022, 9:32am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/9 "2022-11-20T09:32:51Z")

</div>

Hello,  
Thanks, currently progressing now on this, will kepp updated.  
Joel

---

<div class="post-metadata">

**Author:** ![joelguittet](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/joelguittet/32/1064_2.png) [@joelguittet](https://hub.mender.io/u/joelguittet)\
**Post date:** [November 20, 2022, 11:35pm UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/10 "2022-11-20T23:35:51Z")

</div>

Progress on this topic:

- I have created my own tar parser.
- I retrieve the binary from the data.tar file and it looks okay.

Comments:

- The documentation do not indicates the mender file compression is optional at [mender-artifact/artifact-format-v3.md at master · mendersoftware/mender-artifact · GitHub](https://github.com/mendersoftware/mender-artifact/blob/master/Documentation/artifact-format-v3.md) (it is indicated it’s using tar.gz only)
- The “–compression” option of mender-artifact is not well documented (even calling “./mender-artifact --help” do not clearly explain this). I have found in the sources that “–compression none” permit no compression, and the mender file is tar only and not tar.gz 🙂

Continue working on the subject now, no more blocked

Joel

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [November 21, 2022, 8:28am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/11 "2022-11-21T08:28:20Z")

</div>

Ohh, good observation! We will amend this 😸

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [November 23, 2022, 10:26am UTC](https://hub.mender.io/t/writing-a-custom-mender-client-for-an-mcu/5404/12 "2022-11-23T10:26:01Z")

</div>

PR: [docs(artifact-format): Highlight that the compression is optional by oleorhagen · Pull Request #450 · mendersoftware/mender-artifact · GitHub](https://github.com/mendersoftware/mender-artifact/pull/450)
