Technical Blog: https://blog.opensourcesdrlab.com/archives/hackrf-pro-h4m-pro
Github firmware:
https://github.com/portapack-mayhem/mayhem-firmware/releases
https://github.com/OpenSourceSDRLab/mayhem-firmware/releases
Github discussion:
https://github.com/orgs/OpenSourceSDRLab/discussions/5
This blog describes the DFU and mayhem firmware flashing procedure of the H4M Pro with HackRF Pro, and illustrates the configuration methods for battery parameters and RF transmit and receive application function parameters for the Mayhem firmware.
DFU firmware Flashing
Battery Parameter configuration
RF Transmitter & Receiver Application Demo
Version comparison between v2.4.0 and v2.4.0.1
Conclusion
DFU Firmware Flashing
Hold down the DFU button and connect the device to the computer via a USB cable; the unit will enter DFU mode with all indicator lights turned off.
Note: Core difference in DFU mode between HackRF Pro and HackRF One: all indicator lights on HackRF Pro turn off upon entering DFU mode.
Navigate to the firmware flashing directory and double-click to run the mayhem_flasher.bat script. First enter the digit 3 to select the third option [HackRF Pro / PortaPack], then enter the digit 2 to select the second option [Flash DFU then Mayhem (DFU unbrick followed by Mayhem flash in one go)], and wait for the flashing process to complete.
The terminal output Firmware flashed successfully indicates that the Mayhem firmware has been fully flashed. The MCU, FPGA and RF LEDs of HackRF Pro will be on. And the Mayhem firmware will be loaded automatically.
_019f8cd8-7870-762b-9312-9614e93c0153.png)
Battery Parameter Configuration
Enter the main interface of Mayhem and tap the battery icon; the interface displays a default battery capacity of 1500 mAh.
The matching battery supplied with this device has a rated voltage of 3.7 V and a rated energy of 9.25 Wh. Using the formula: Capacity (mAh) = Energy (Wh) ÷ Voltage (V) × 1000, the actual capacity is calculated as 2500 mAh.
_019f8cd8-84ef-71ac-b824-64efe49feca9.png)
Tap Settings on the page to open the configuration interface, rotate the adjustment scroll wheel, change the default value of 1500 mAh to 2500 mAh, and save the parameters.
_019f8cd8-86af-714b-9ab4-96155c53c353.png)
Return to the main interface and open the battery page again; the interface shows the capacity has been updated to 2500 mAh, confirming the battery capacity parameter modification took effect.
_019f8cd8-8945-726d-99db-ea18a77bfe41.png)
RF Transmitter & Receiver Application Demo
This presentation supports transceiving WFM, APRS, ADS-B, POCSAG, NFM and BLE signals with configurable modes, frequencies and bandwidths for routine signal processing.
WFM audio receiver
This experiment is for broadcast reception. Navigate to the main interface of the Mayhem firmware and tap to switch to the Receive page. Select the Audio mode, then switch to the WFM wideband FM playback standard. The frequency can be customized as needed; it is set to 100.6 MHz in this experiment. Gain parameters can remain at default values.
_019f8cd8-8bfc-722f-9a12-5401f6d3f9d6.png)
NFM Transceiving Performance Test
This experiment is carried out for narrowband FM (NFM) signal transmission and reception testing, with two devices serving as the transmitter and receiver respectively.
On the receiving device, tap to enter the Receive page, select the Audio RX channel and switch to the NFM demodulation mode. On the transmitting device, open the Transmit interface, select the Signal Generator function and set the operating frequency to 466.1750 MHz. Point-to-point communication can only be realized when the transmitter and receiver are tuned to the same frequency. Accordingly, set the receiver frequency to 466.1750 MHz synchronously, and retain the default gain parameters.
Once transmission is activated on the transmitter, voice signals can be instantly captured by the receiver. The default transmission modulation mode is CW. If the modulation scheme is switched to FM prior to transmission startup, the timbre of demodulated audio output from the receiver will show an obvious difference.
_019f8cd8-9043-7374-99d6-8f76a1a6b66c.png)
APRS Two-Way Communication Test
This experiment is an APRS two-way communication test.
Open the transmit interface on the transmitting device and enter the APRS TX page; tap to enter the receive page on the receiving device and select APRS RX mode. Set the operating frequency of both devices to 144.3900 MHz. Point-to-point communication demands identical frequency settings on transmitter and receiver. The SSID can be configured arbitrarily, and default gain parameters are adopted.
Tap Set on the transmitting interface, edit the message to be transmitted and click OK; the receiving terminal will receive the transmitted content immediately.
_019f8cd8-9674-72bb-9e3d-2aae0638822c.png)
Aviation ADS-B Signal Reception Function Test
This experiment is an aviation ADS-B signal reception function test。
Switch the receiving device to the Receive interface and select ADS-B mode; open the Transmit interface on the transmitting device and enter the ADS-B configuration page. Check Transmit position on the transmitter, configure arbitrary simulated GPS location data, then start transmission. The receiver will capture signals after a short delay, and the specific coordinates of the simulated aircraft can be displayed on the interface.
_019f8cd8-9a6f-707b-8b48-3272e70414dd.png)
If the LNA and UGA gain parameters of the receiving terminal are both set to 24, restart transmission on the transmitter, the receiver can capture ADS-B signals instantly with greatly improved response speed.
_019f8cd8-9d4a-75e3-b899-8057938765cf.png)
POCSAG Transmit & Receive Performance Test
This experiment is a POCSAG transmit-receive performance test.
Switch the receiving device to the Receive page and select POCSAG RX mode; open the Transmit interface on the transmitting device and enter the POCSAG TX configuration page.
The transmitter sends PORTAPACK by default with alphanumeric message type. After transmission is triggered, the receiver can receive PORTAPACK messages. The transmitter and receiver share the same operating frequency with default gain settings.
_019f8cd8-a144-72a2-84c6-399023553ca5.png)
BLE Transmit & Receive Performance Test
This experiment is a BLE Bluetooth Low Energy transmit and receive performance test.
On the transmitting device, enter the transmit interface and open the BLE TX configuration page. On the receiving device, switch to the receive interface and select the BLE RX receiving mode, set the receiver to Auto mode and set Sort to Hits.
_019f8cd8-a621-741f-a535-38c3badc2e66.png)
On the transmitter, click Open file and select any file, enable BLE TX, adjust the gain to 16, turn on Loop mode and start transmission. On the receiver, click clear to clear records and refresh the page. A device with MAC address 01:02:03:04:05:06 will keep showing continuous hits at the top of the interface, and the MAC address parsed by the receiver matches this value. The receiver gain should be set to 24 as the reference value for the fastest hit capture speed; modifying other parameters will slow down the capture rate.
Version comparison between v2.4.0 and v2.4.0.1
v2.4.0.1 optimizes wideband FM and BLE functions to boost signal, display and audio, and fix occasional Bluetooth reception issues.
Optimization of WFM Broadcast Reception Experience
The operation procedure for WFM broadcast reception remains consistent with v2.4.0.
Navigate to the main interface of the Mayhem firmware and tap to switch to the Receive page. Select the Audio mode, then switch to the WFM wideband FM playback standard. The frequency can be customized as needed; it is set to 100.6 MHz in this experiment. Gain parameters can remain at default values.
This version delivers a clearer waterfall display and improved intelligibility of human voice.
_019f8cd8-a947-73da-86ae-fb84b50c9375.png)
Optimization of BLE Transmit and Reception
The operation process for BLE transmission and reception is consistent with version v2.4.0
This experiment is a BLE Bluetooth Low Energy transmit and receive performance test
Open the transmit interface on the transmitter and the receive interface on the receiver, then select BLE RX mode on the receiver. Set the receiver to Auto mode and set Sort to Hits.
On the transmitter, enter the BLE TX configuration page, click Open file to import any file, enable BLE TX, set the gain to 24, turn on Loop cyclic transmission, and start transmitting signals. On the receiver, click clear to clear logs and refresh the interface. Devices with MAC address 01:02:03:04:05:06 will continuously appear in hit records at the top, and the parsed MAC matches this address. A gain of 24 is recommended as the baseline for the receiver to achieve the fastest signal capture; adjusting the gain will slow down signal detection.
The occasional signal reception failure issue existing in the old version has been fixed in the new release.
Conclusion
The full deployment and functional verification process of the complete H4M PortaPack Pro unit has been fully finished.
We finished Mayhem firmware one-click DFU flashing, original 18650 battery calibration, multi-standard RF transceiver debugging, and performance tests of Mayhem v2.4.0 & v2.4.0.1.
After full setup, users can receive modulated radio signals, demodulate audio and data in real time, establish RF point-to-point analog links, and configure gain and battery parameters to achieve optimal performance of the H4M Pro SDR.