nRF Connect SDK v3.4.1 Release Notes
nRF Connect SDK delivers reference software and supporting libraries for developing low-power wireless applications with Nordic Semiconductor products in the nRF52, nRF53, nRF54, nRF70, and nRF91 Series. The SDK includes open source projects (TF-M, MCUboot, OpenThread, Matter, and the Zephyr RTOS), which are continuously integrated and redistributed with the SDK.
Release notes might refer to “experimental” support for features, which indicates that the feature is incomplete in functionality or verification, and can be expected to change in future releases. To learn more, see Software maturity levels.
Highlights
This patch release adds the following changes on top of the nRF Connect SDK v3.4.0:
The nRF Connect SDK v3.4.1 is based on Zephyr 4.4.2, Mbed TLS 4.1.1, and TF-M 2.3.1.
This patch release is part of the v3.4 release branch, which has long-term support (LTS) for a period of five years. During this period, patch releases will provide updates for security vulnerabilities and critical bug fixes. These patch releases will not contain breaking changes unless security fixes require them.
The v3.4 release branch is the last nRF Connect SDK release branch that includes support for nRF52 Series devices. The nRF52 Series devices are considered feature complete, and support for them will be removed from samples and applications in the main branch.
Added the following supported features:
CAN:
Power management support has been added to the nRF CAN FD driver. The nRF54H20 SoC can now enter sleep mode when the CAN controller is enabled with
CONFIG_CANset toybut not started withcan_start().
FMN:
The FMN extension has been updated to the FMN R3 specification. For details about the implementation and compliance, see the extension documentation.
SysCtrl WDT:
The SysCtrl WDT service has been added for the nRF54H20 SoC. It enables continuous low-power WDT operation.
Added the following experimental features:
Experimental support for the nRF54LC10A SoC.
Add-ons:
New HID add-on:
The nRF Desktop HID application will be moved to a dedicated HID add-on. Its existing feature set will be maintained in the nRF Connect SDK v3.4 LTS releases, but new features will be introduced only in the add-on.
Deprecated:
Deprecated features will not be removed from the LTS branch. It is recommended that all new designs using Nordic devices exclude deprecated features for active development and deployment.
Release tag
The release tag for the nRF Connect SDK manifest repository (https://github.com/nrfconnect/sdk-nrf) is v3.4.1.
Check the west.yml file for the corresponding tags in the project repositories.
To use this release, check out the tag in the manifest repository and run west update.
See Install the nRF Connect SDK code and toolchain and Updating the repositories for more information.
For information on the included repositories and revisions, see Repositories and revisions for v3.4.1.
IDE and tool support
nRF Connect extension for Visual Studio Code is the recommended IDE for nRF Connect SDK v3.4.1. See the Installation section for more information about supported operating systems and toolchain.
Supported modem firmware
See the following documentation for an overview of which modem firmware versions have been tested with this version of the nRF Connect SDK:
Use the latest version of the Programmer app of nRF Connect for Desktop to update the modem firmware. See Programming nRF91 Series DK firmware for instructions.
Known issues
Known issues are only tracked for the latest official release. See known issues for nRF Connect SDK v3.4.1 for the list of issues valid for the latest release.
Changelog
The following sections provide detailed lists of changes by component.
Bootloaders and DFU
Added:
The hidden
CONFIG_NCS_MCUBOOT_ENCRYPTION_HMAC_SHA256Kconfig option to select HMAC-SHA256 with X25519 for compatibility with existing projects that use it. The option is hidden and requires addition of a Kconfig override in your project. This is intentional as HMAC-SHA512 is recommended over HMAC-SHA256.Support for the application core of the nRF54LS05A SoC to MCUboot and secure boot sysbuild, including the secure boot locking and immutable region handling features aligned with the nRF54LS05B SoC.
Fixed:
Sequential updates on the nRF5340 SoC. The address-based detection of the update candidate type allows placing the network core update candidate in the same partition used for the application update candidate. The build system no longer requires dedicated slots for the network core update candidate. You can enable software-based downgrade prevention for network core updates. MCUboot now erases the secondary slot after the network core is updated.
Developing with nRF54L Series
Added support for the nRF54LC10A SoC and the nrf54lc10dk board.
Protocols
This section provides detailed lists of changes by protocol. See Samples for lists of changes for the protocol-related samples.
Bluetooth Mesh
Fixed an issue where an LPN that terminated a friendship by sending a Friend Clear message with TTL set to
0never received the Friend Clear Confirm message from the Friend node.
Matter
Replaced the tables on the RAM and flash memory requirements and Reference Matter memory layouts pages with memory layout charts.
Security
Updated:
Oberon PSA Crypto from v2.0.0 to v2.1.0. The new version has minor updates in internal APIs, restructures the directory hierarchy, and improves native support for built-in keys.
nrf_cc3xx_platform and nrf_cc3xx_mbedcrypto libraries to version v0.9.23. Improved PSA driver error reporting and fixed an issue that caused incorrect authentication tag generation in GCM when multiple calls to
psa_aead_update_ad()were made.
Trusted Firmware-M (TF-M)
Updated TF-M to v2.3.1 (from v2.3.0). For more information, see the upstream TF-M 2.3.1 release notes.
Mbed TLS
Updated Mbed TLS to v4.1.1 (from v4.1.0) and TF-PSA-Crypto to v1.1.1 (from v1.1.0). For more information, see the upstream Mbed TLS 4.1.1 release notes and TF-PSA-Crypto 1.1.1 release notes.
Applications
This section provides detailed lists of changes by application.
nRF Desktop
Future development of the nRF Desktop HID application reference design will move to a dedicated nRF Connect SDK Add-on (
HID Add-on). Existing feature set will be maintained in the nRF Connect SDK 3.4 long-term support (LTS) releases, but new features will be introduced only in the Add-on. The add-on will support the nRF54L Series.Added:
Support for the
nrf54ls05dk/nrf54ls05a/cpuappandnrf54lc10dk/nrf54lc10a/cpuappboard targets.The
release_fast_pairbuild type for thenrf54ls05dk/nrf54ls05a/cpuappandnrf54ls05dk/nrf54ls05b/cpuappboard targets. The configuration acts as a HID mouse with Fast Pair support. It uses MCUboot in direct-xip mode with software-based image signature verification.
Samples
This section provides detailed lists of changes by sample.
Bluetooth samples
Bluetooth: Central HIDS, Bluetooth: Peripheral HIDS keyboard, and Bluetooth: Peripheral HIDS mouse samples:
Added support for the
nrf54ls05dk/nrf54ls05a/cpuapp,nrf54ls05dk/nrf54ls05b/cpuapp,nrf54lc10dk/nrf54lc10a/cpuapp, andnrf54lc10dk/nrf54lc10a/cpuapp/nsboard targets.
Bluetooth Mesh samples
Bluetooth Mesh: Light switch sample:
Added support for the
nrf54l15tag/nrf54l15/cpuappboard target in the LPN configuration.
Bluetooth Fast Pair samples
Added experimental support for the
nrf54ls05dk/nrf54ls05a/cpuappandnrf54lc10dk/nrf54lc10a/cpuappboard targets in all Bluetooth Fast Pair samples.Bluetooth Fast Pair: Locator tag sample:
Updated:
The TX power calibration for the
nrf54l15tag/nrf54l15/cpuappboard target. TheCONFIG_BT_ADV_PROV_TX_POWER_CORRECTION_VALandCONFIG_BT_FAST_PAIR_FHN_TX_POWER_CORRECTION_VALKconfig options were changed from-13dBm to-11dBm to meet the Fast Pair distance certification requirements.The TX power calibration for the
nrf54lm20dk/nrf54lm20a/cpuappandnrf54lm20dk/nrf54lm20b/cpuappboard targets. TheCONFIG_BT_ADV_PROV_TX_POWER_CORRECTION_VALandCONFIG_BT_FAST_PAIR_FHN_TX_POWER_CORRECTION_VALKconfig options were changed from-15dBm to-2dBm to meet the Fast Pair distance certification requirements.The location of the
CONFIG_BT_ADV_PROV_TX_POWER_CORRECTION_VALandCONFIG_BT_FAST_PAIR_FHN_TX_POWER_CORRECTION_VALKconfig options. The options were moved from the sample-wide configuration files to the board configuration files in theconfiguration/boardsdirectory, as the TX power correction is hardware-specific. Every supported board target now declares its own calibration.The sample configuration to use the DULT API variant v2 (
CONFIG_DULT_API_VARIANT_V2).
Bluetooth Fast Pair: Input device sample:
Added experimental support for the
nrf54lc10dk/nrf54lc10a/cpuapp/nsboard target.
Cryptography samples
Added support for the nRF54LC10A SoC (with and without TF-M) in the crypto samples.
DFU samples
Added support for the
nrf54ls05dk/nrf54ls05a/cpuappandnrf54ls05dk/nrf54ls05b/cpuappboard targets to the following samples:MCUboot with encryption enabled, with ECIES-P-256 image encryption using
CONFIG_BOOT_ECDSA_NRF_OBERONorCONFIG_BOOT_ECDSA_PSA.
Enhanced ShockBurst samples
Added support for the
nrf54lc10dk/nrf54lc10a/cpuapp,nrf54lc10dk/nrf54lc10a/cpuapp/ns, andnrf54ls05dk/nrf54ls05a/cpuappboard targets in all samples.
Matter samples
Added support for the
nrf54lc10dk/nrf54lc10a/cpuappboard target for the following samples:Matter template sample
Matter temperature sensor sample
DFU is not supported on this board target, as the nRF54LC10 DK is not equipped with external flash. See External flash for more information.
Fixed an issue where the binding table was not printed correctly when the cluster ID was not set.
Trusted Firmware-M (TF-M) samples
Added support for the nRF54LC10A SoC in the TF-M samples.
Thread samples
Added experimental support for the nRF54LC10A SoC to all Thread samples.
Scripts
This section provides detailed lists of changes by script.
HID configurator
Future development of the HID configurator for nRF Desktop will move to a dedicated nRF Connect SDK add-on (
HID Add-on). Existing feature set will be maintained in the nRF Connect SDK 3.4 long-term support (LTS) releases, but new features will be introduced only in the add-on.
Libraries
This section provides detailed lists of changes by library.
Bluetooth libraries and services
GATT Human Interface Device (HID) Service library:
Added support for runtime customization of connection parameters for a given HID SCI mode through the newly added
bt_hids_sci_mode_conn_rate_param_get()API.
DTM 2-wire UART to HCI Converter library:
Added:
The
CONFIG_DTM_TWOWIRE_TO_HCI_SDC_VS_COMMANDSKconfig option to support vendor-specific DTM 2-wire commands. The option is enabled by default ifCONFIG_BT_HCI_VSis enabled.A vendor-specific DTM 2-wire command for constant carrier transmission.
Google Fast Pair Service (GFPS) library:
Added integration of the Find Hub Network (FHN) extension with the DULT API variant v2. With this integration, the FHN extension can coexist during the pre-association window with other accessory-locating networks that are registered as DULT users. The FHN extension now ties the DULT association to its provisioning state. It also reports the DULT ownership state, which is the association state, through the new
bt_fast_pair_fhn_info_cb.dult_ownership_state_changedcallback.
Libraries for NFC
Parser for messages and records:
Fixed an issue where parsing a malformed long-format NDEF record could produce an incorrect payload length. The parser now validates type, ID, and payload lengths against the remaining input buffer.
Other libraries
RAM power-down library:
Added:
Support for the nRF54LC10A SoC and the nRF54LS05A SoC
ECIES-P-256 encrypted image support when using
CONFIG_BOOT_ECDSA_NRF_OBERON. It uses theocryptosoftware backend instead of TinyCrypt.ECIES-P-256 encrypted image support for the
CONFIG_BOOT_ECDSA_PSApath by auto-selecting the required PSA algorithms.
Detecting Unwanted Location Trackers (DULT) library:
Added:
The DULT API variant v2 (
CONFIG_DULT_API_VARIANT_V2), which supports registering more than one accessory-locating network at the same time. TheCONFIG_DULT_USER_MAXKconfig option sets the maximum number of registered networks. See the Detecting Unwanted Location Trackers (DULT) integration guide for details. The following API elements are exclusive to this variant:The
dult_user_unregister()function for performing the final teardown of a registered user. In contrast, thedult_reset()function only releases the association and keeps the user registered.The
dult_multi_user_cb_register()function for notifying the registered users about the DULT association arbitration outcome.The
dult_multi_user_conn_claim()function for routing the Accessory Non-owner Service operations that arrive before the DULT association to the DULT user that owns the Bluetooth connection.
The
dult_user_is_associated()anddult_is_any_associated()functions for checking the DULT association state.The
dult_bt_adv_data_fill()function and thedult_bt_adv_datastructure for serializing the DULT location-enabled advertising payload.The
dult_bt_anos_cbcallback structure and thedult_bt_anos_cb_register()function that let a network layered on top of DULT override the default separated-state access gate for the Accessory Information operations.Support for the optional
Get_Network_Versionoperation through the newnetwork_versionfield of thedult_userstructure.The
CONFIG_DULT_ACCESSORY_TYPE_SMALLandCONFIG_DULT_ACCESSORY_TYPE_LARGEKconfig options for declaring the accessory size. The declared size controls whether the mandatory accessory capabilities are enforced during the DULT user registration.A runtime override of the motion detector test timing through the
dult_test_motion_detector_separated_ut_period_set()function. This override is available when you enable theCONFIG_DULT_MOTION_DETECTOR_TEST_MODEKconfig option.
Updated:
The DULT public headers by moving them to a dedicated
include/dult/directory. Includedult/dult.hinstead of the deprecateddult.h.The
struct dult_firmware_versionstructure by renaming it todult_version. The deprecateddult.hheader still provides thedult_firmware_versionalias to maintain backward compatibility.
Deprecated the DULT API variant v1 (
CONFIG_DULT_API_VARIANT_V1), which remains the default for backward compatibility.
Integrations
This section provides detailed lists of changes by integration.
DULT integration
Updated the Detecting Unwanted Location Trackers (DULT) integration guide to describe both DULT API variants, the multi-user coexistence workflow, and the serialization of the location-enabled advertising payload. The guide also describes the Accessory Non-owner Service access policy, including access before the accessory is associated with an accessory-locating network.
Google Fast Pair integration
Updated the Google Fast Pair integration guide to describe how the FHN extension claims and releases the DULT association in each DULT API variant. The guide also describes how to handle the new
bt_fast_pair_fhn_info_cb.dult_ownership_state_changedcallback when your product registers multiple accessory-locating networks.
Memfault integration
Updated Memfault to version 1.40.1. See the Memfault firmware SDK changelog for details.
nRF Cloud integration
Added the
CONFIG_NRF_CLOUD_FOTA_POLL_JOB_CHECK_PROGRESS_THRESHOLDKconfig option to the nRF Cloud FOTA polling helpers, allowing the progress-based FOTA job re-check to be configured or disabled.Fixed a memory leak in the nRF Cloud FOTA polling helpers where the temporary job info returned by each FOTA job check was not released on all code paths.
MCUboot
The MCUboot fork in nRF Connect SDK (sdk-mcuboot) contains all commits from the upstream MCUboot repository up to and including 8d14eebfe0b7402ebdf77ce1b99ba1a3793670e9, with some nRF Connect SDK specific additions.
The code for integrating MCUboot into nRF Connect SDK is located in the ncs/nrf/modules/mcuboot folder.
The following list summarizes both the main changes inherited from upstream MCUboot and the main changes applied to the nRF Connect SDK specific additions:
Added:
Support for the nRF54LC10A SoC.
Support for compiling multiple image verification keys into MCUboot. The
CONFIG_BOOT_SIGNATURE_KEY_FILEKconfig option accepts a comma-separated list of PEM files. Only public key material is embedded in the bootloader image. This enables a production or development signing custody model in which, for example, an updatable development bootloader can boot images signed with either key, while a production bootloader embeds only the production verification key. MCUbootimgtooladds thekeyinfosubcommand and the--name-suffixoption forgetpubandgetpubhashto support multiple keys embedded in the bootloader image.Experimental support for the nRF54LS05A SoC.
Updated:
The
CONFIG_BOOT_ECDSA_NRF_OBERONKconfig option. This option has been reinstated and is no longer deprecated. It has also been configured as the default ECDSA P-256 implementation for the nRF54LS05A and nRF54LS05B SoCs.MCUboot to feed the watchdog more frequently during the following time-consuming operations to prevent watchdog timeouts:
Full slot erase procedures
The move-sectors-up loop and sectors-swap loop of the swap-move algorithm
The hash calculation loop during image hash calculation
Fixed an issue where UICR was not provisioned with monotonic counter structures when
SB_CONFIG_MCUBOOT_HARDWARE_DOWNGRADE_PREVENTIONwas enabled, MCUboot was the only bootloader, and Partition Manager was disabled.
Zephyr
The Zephyr fork in nRF Connect SDK (sdk-zephyr) contains all commits from the upstream Zephyr repository up to and including 684c9e8f32e4373a21098559f748f06915f950c9.
For a complete list of nRF Connect SDK specific commits and cherry-picked commits since v3.4.0, run the following command:
git log --oneline manifest-rev ^ncs-v3.4.0
Additions specific to nRF Connect SDK
Added the release.yaml file with device classification support overview.
Documentation
Added the Kconfig diff page, displaying differences between available Kconfig options across releases. To generate the new documentation page, set the
KCONFIGDIFFCMake option toON.Updated:
The nRF54L Series bootloader RRAM protection documentation page to explain the memory protection features of the bootloader on the nRF54L Series.
The IronSide SE ABI compatibility page to link to the IronSide SE binaries changelog on the main branch for the full list of changes to IronSide SE.