Simulate a cellular modem and MQTT without a full network
Category: Engineering
You can test the main firmware path of a telematics device without a cellular network. The microcontroller can send AT commands. The microcontroller can read a Global Navigation Satellite System (GNSS) fix. The microcontroller can publish a Message Queuing Telemetry Transport (MQTT) message. The microcontroller can verify the payload.
LabWired models this path. LabWired does not model a complete cellular network.
A physical test bench needs a modem, a SIM, an antenna, and a broker account. These dependencies can make automated tests slow. These dependencies can make automated tests difficult to reproduce.
The virtual lab tests a smaller path. The path is well defined.
- Send Quectel-style commands such as
AT+QGPS*andAT+QMT*. - Parse a GNSS fix.
- Publish a JSON message with latitude, longitude, and source data.
- Read the published message from the test environment.
The lab does not simulate the LTE-M air interface or the NB-IoT air interface. The lab does not provide a real MQTT 3.1.1 broker.
In scope and out of scope
| In scope | Out of scope |
|---|---|
| BG770A AT surface over UART (QGPS, QMT open/conn/pub/sub) | Full LTE-M/NB-IoT air interface / RAN / EPC |
GNSS reply shapes (+QGPSLOC) with lab coordinates | Real constellation dynamics |
| SimMqttFabric stores publishes for inspection and collection | Real MQTT broker, auth, retained sessions |
| Path-loss CSQ from a shared RF medium | Accurate link-budget engineering |
| Headless io-smoke in CI (UART + fabric payload) | Carrier certification |
These limits are important. The lab verifies firmware behavior at the modem interface. The lab does not verify a carrier network. The lab does not certify a radio design.
MCU, modem AT, and AirBus
The demo uses a virtual STM32H735 microcontroller.
- USART1 connects to the Quectel BG770A model.
- USART3 provides the console and the AT transcript.
- SPI1 and PA4 connect to a compact ILI9341 display strip.
The display shows latitude, longitude, and modem status.
The network peer is SimMqttFabric. SimMqttFabric runs on the lab AirBus with the shared path-loss RfMedium.
MCU ──USART──► BG770A AT model
│
├── RfMedium (range → CSQ)
└── SimMqttFabric (QMTPUB → collect)
The attach_lab_air API connects the modem to this environment. The command-line interface creates private lab air when a modem is present. The Playground connects the same API to a shared AirBus.
A multi-node World can place several user devices on one fabric. One node can publish while another node subscribes.
Send and collect
The firmware uses the same AT command sequence as on a physical modem.
AT+QGPS=1
AT+QGPSLOC=0 → parse lat/lon
AT+QMTOPEN=0,"broker…",1883
AT+QMTCONN=0,"client"
AT+QMTPUB=0,0,0,0,"telematics/location",N
> {"lat":…,"lon":…,"src":"qgpsloc"}
Ctrl-Z
→ +QMTPUB: 0,0,0
SimMqttFabric stores the payload when the firmware submits the payload. Tests can then inspect the stored message.
- The headless smoke test checks the UART for
GPS fix. The test checks the UART forlocation published. The test checks the UART for+QMTPUB:. The test also checks thatmqtt_fabriccontains the JSON. The topic istelematics/location. - The Playground shows the topic and the payload in the fabric strip.
- Wasm and API clients can use
mqtt_fabric_has_publish,mqtt_fabric_last_payload, andmqtt_fabric_inspect. The oldercellular_*aliases still work.
The same fabric also supports QMTSUB. A subscription can receive +QMTRECV from loopback traffic. A subscription can receive +QMTRECV from a second virtual device.
Radio quality without a radio
With an RfMedium attached, simulated distance changes the received signal strength. The distance is between the user device and the cell. The model converts path loss to dBm. The model then converts that dBm value to the CSQ value of the modem.
The modem reports no service if the signal falls below the configured limit. MQTT operations follow the no-service state. An open request fails with +QMTOPEN: id,1. A publish does not report success.
This test shows how the firmware handles signal loss. This test does not validate a physical antenna. This test does not validate a link budget.
Try the lab
Open Playground board h735-telematics-lab. Start the simulation. Open Serial to view the AT log. Inspect the MQTT payload in the fabric strip.
Run the command-line test from labwired-core.
cargo build -p h735-telematics-lab --release --target thumbv7em-none-eabi
cargo run -q -p labwired-cli -- test \
--script examples/h735-telematics-lab/io-smoke.yaml \
--output-dir /tmp/h735-out --no-uart-stdout
Find the two-device publisher and subscriber test in examples/h735-telematics-lab/env-two-ue-smoke.yaml.
The test list
The model has tests for these results:
- Fabric publish
- Loopback
+QMTRECV - Signal-dependent open failure
- GNSS output and publish output on UART
- The stored fabric payload
- Message delivery between two virtual devices
The example source is in examples/h735-telematics-lab/. The SimMqttFabric implementation is in LabWired core.
This setup verifies the firmware path for the modem interface before hardware is available. You still need tests with a physical modem, a carrier, a broker, an antenna, and an RF environment.