docs: readme.md
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# UTAT Firmware Development MCUBoot POC
|
||||
# UTAT Device Firmware Upgrade with MCUboot
|
||||
|
||||
Documentation of the steps taken to implement MCUBoot.
|
||||
Documentation of the steps taken to implement MCUBoot for Device Firmware Upgrades.
|
||||
|
||||
## Environnment config
|
||||
Use the environment written in flake.nix by running `nix develop`
|
||||
@@ -28,10 +28,6 @@ MCUBoot is a bootloader for Zephyr, which allows multiple firmwares to exist on
|
||||
|
||||
[Abstract MCUBoot Guide](https://docs.mcuboot.com/readme-zephyr.html)
|
||||
|
||||
```sh
|
||||
west build -p always -b nucleo_g431rb samples/basic/blinky
|
||||
west flash --runner pyocd # had to su root first to run this (after running nix develop)
|
||||
```
|
||||
|
||||
|
||||
## Configure partition sizes
|
||||
@@ -56,66 +52,158 @@ I created a partition for MCUBoot, two firmware slots, and additional storage in
|
||||
boot_partition: partition@0 {
|
||||
compatible = "zephyr,mapped-partition";
|
||||
label = "mcuboot";
|
||||
reg = <0x00000000 0x00008000>;
|
||||
reg = <0x00000000 0x0000C000>;
|
||||
};
|
||||
|
||||
slot0_partition: partition@8000 {
|
||||
slot0_partition: partition@C000 {
|
||||
compatible = "zephyr,mapped-partition";
|
||||
label = "image-0";
|
||||
reg = <0x00008000 0x00010000>;
|
||||
reg = <0x0000C000 0x0000A000>;
|
||||
};
|
||||
|
||||
slot1_partition: partition@10000 {
|
||||
slot1_partition: partition@14000 {
|
||||
compatible = "zephyr,mapped-partition";
|
||||
label = "image-1";
|
||||
reg = <0x00010000 0x0018000>;
|
||||
};
|
||||
|
||||
storage_partition: partition@18000 {
|
||||
compatible = "zephyr,mapped-partition";
|
||||
label = "storage";
|
||||
reg = <0x00018000 0x00020000>;
|
||||
reg = <0x00016000 0x0000A000>;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
```
|
||||
|
||||
## Try to build MCUBoot
|
||||
(Originally my partitions were 8000B each but MCUBoot would not build as its boot partition was too small. By using direct-xip there is no need for additional storage for copying images either.)
|
||||
|
||||
|
||||
## Enable building for MCUboot with direct-xip
|
||||
Add these lines to `bootloader/mcuboot/boot/zephyr/prj.conf`
|
||||
|
||||
```sh
|
||||
west build -p always -b nucleo_g431rb bootloader/mcuboot/boot/zephyr
|
||||
### Must be enabled to build applications for MCUboot
|
||||
CONFIG_BOOTLOADER_MCUBOOT=y
|
||||
### Allows in-place execution
|
||||
CONFIG_BOOT_DIRECT_XIP=y
|
||||
### Allows switching the image
|
||||
CONFIG_BOOT_DIRECT_XIP_REVERT=y
|
||||
```
|
||||
|
||||
Then in `zephyr/samples/basic/blinky/prj.conf` and `zephyr/samples/basic/blinkyslow/prj.conf` add the following:
|
||||
```sh
|
||||
CONFIG_BOOTLOADER_MCUBOOT=y
|
||||
CONFIG_IMG_MANAGER=y
|
||||
CONFIG_FLASH=y
|
||||
CONFIG_REBOOT=y
|
||||
```
|
||||
|
||||
## Enable switching firmware
|
||||
Each time a peice of firmware is run, set the other one as the upgrade so it runs next time. Add this to the code early in main:
|
||||
|
||||
```c
|
||||
#include <zephyr/dfu/mcuboot.h>
|
||||
#include <zephyr/sys/reboot.h>
|
||||
|
||||
int main() {
|
||||
/* Confirm ourselves so MCUboot doesn't revert us on a later reset */
|
||||
if (!boot_is_img_confirmed()) {
|
||||
boot_write_img_confirmed();
|
||||
}
|
||||
|
||||
/* Arm a permanent swap so the other image runs after the next reset */
|
||||
boot_request_upgrade(BOOT_UPGRADE_PERMANENT);
|
||||
...
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
|
||||
old below
|
||||
## Build the blinkys
|
||||
|
||||
The west build `-DSB_CONFIG_BOOTLOADER_MCUBOOT=y` flag enables MCUboot on the blinkys.
|
||||
|
||||
```sh
|
||||
west build -p always -b nucleo_g431rb zephyr/samples/basic/blinky -d build/blinky --sysbuild -- -DSB_CONFIG_BOOTLOADER_MCUBOOT=y #-CONFIG_MCUBOOT_SERIAL_DIRECT_IMAGE_UPLOAD=y
|
||||
|
||||
west build -p always -b nucleo_g431rb zephyr/samples/basic/blinkyslow -d build/blinkyslow --sysbuild -- -DSB_CONFIG_BOOTLOADER_MCUBOOT=y
|
||||
```
|
||||
# Create a private key: https://docs.mcuboot.com/readme-zephyr.html
|
||||
python ./bootloader/mcuboot/scripts/imgtool.py keygen -k private.pem -t rsa-2048
|
||||
|
||||
|
||||
## Flash the blinkys
|
||||
```sh
|
||||
pyocd flash -t stm32g431rbtx build
|
||||
/blinky/mcuboot/zephyr/zephyr.bin
|
||||
|
||||
pyocd flash -t stm32g431rbtx --base-address 0x0000C000 build/blinky/blinky/zephyr/zephyr.bin
|
||||
```
|
||||
|
||||
(blinkyslow is a clone of blinky with a different frequency)
|
||||
|
||||
|
||||
## Set up crypto
|
||||
```sh
|
||||
python bootloader/mcuboot/scripts/imgtool.py keygen -k private.pem -t rsa-2048
|
||||
|
||||
# Create its public key
|
||||
openssl rsa -in private.pem -pubout > public.pem
|
||||
```
|
||||
|
||||
# Set up signing: https://docs.mcuboot.com/readme-zephyr.html
|
||||
# ./bootloader/mcuboot/samples/zephyr/Makefile
|
||||
## Sign the blinkys
|
||||
```sh
|
||||
python bootloader/mcuboot/scripts/imgtool.py sign \
|
||||
--key mykey.pem \
|
||||
--key private.pem \
|
||||
--header-size 0x200 \
|
||||
--pad-header \
|
||||
--align 8 \
|
||||
--version 1.2 \
|
||||
--slot-size 0x8000 \
|
||||
./
|
||||
build/blinky/zephyr/zephyr.bin \
|
||||
blinky-signed.bin
|
||||
|
||||
python bootloader/mcuboot/scripts/imgtool.py sign \
|
||||
--key private.pem \
|
||||
--header-size 0x200 \
|
||||
--pad-header \
|
||||
--align 8 \
|
||||
--version 1.2 \
|
||||
--slot-size 0x8000 \
|
||||
build/blinkyslow/zephyr/zephyr.bin \
|
||||
blinkyslow-signed.bin
|
||||
```
|
||||
|
||||
|
||||
# Add the key file path to the KConfig https://docs.zephyrproject.org/latest/build/kconfig/setting.html
|
||||
|
||||
## Build the firmware
|
||||
|
||||
```sh
|
||||
west build -p always -b nucleo_g431rb -d build_mcuboot bootloader/mcuboot/boot/zephyr --
|
||||
|
||||
west build -p always -b nucleo_g431rb -d build_fast zephyr/samples/basic/blinky
|
||||
|
||||
west build -p always -b nucleo_g431rb -d build_slow zephyr/samples/basic/blinkyslow
|
||||
```
|
||||
|
||||
## Flash the firmware
|
||||
|
||||
`su root` allows flashing to usb devices, run `nix develop` again if using it.
|
||||
|
||||
`flash0@0x08000000` in `zephyr/dts/arm/st/g4/stm32g4.dtsi`
|
||||
```sh
|
||||
pyocd flash -t stm32g431rbtx build_mcuboot/zephyr/zephyr.hex
|
||||
|
||||
pyocd flash -t stm32g431rbtx --base-address 0x0800C000 build_fast/zephyr/zephyr.bin
|
||||
|
||||
pyocd flash -t stm32g431rbtx --base-address 0x08014000 build_slow/zephyr/zephyr.bin
|
||||
```
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
<!-- # Add the key file path to the KConfig https://docs.zephyrproject.org/latest/build/kconfig/setting.html
|
||||
echo "
|
||||
|
||||
# Set the key file
|
||||
CONFIG_BOOT_SIGNATURE_KEY_FILE=public.pem" >> "./zephyr/boards/st/nucleo_g431rb/nucleo_g431rb_defconfig"
|
||||
CONFIG_BOOT_SIGNATURE_KEY_FILE=public.pem" >> "./zephyr/boards/st/nucleo_g431rb/nucleo_g431rb_defconfig" -->
|
||||
|
||||
|
||||
|
||||
west build -p always -b nucleo_g431rb bootloader/mcuboot/boot/zephyr -d build/mcuboot -- -DEXTRA_CONF_FILE=mcuboot-nucleo-g431rb.conf
|
||||
<!-- west build -p always -b nucleo_g431rb bootloader/mcuboot/boot/zephyr -d build/mcuboot -- -DEXTRA_CONF_FILE=mcuboot-nucleo-g431rb.conf
|
||||
west flash -d build/mcuboot --runner pyocd # (as root, with nix develop)
|
||||
|
||||
cd zephyr
|
||||
@@ -126,4 +214,5 @@ west flash -d build/app --runner pyocd # (as root, with nix develop)
|
||||
# Package 2
|
||||
west build -p always -b nucleo_g431rb samples/basic/blinkyslow -d build/blinkyslow -- -DCONFIG_BOOTLOADER_MCUBOOT=y -DCONFIG_MCUBOOT_GENERATE_UNSIGNED_IMAGE=y
|
||||
pyocd flash --target stm32g431rbtx --base-address 0x08014800 build/blinkyslow/zephyr/zephyr.signed.hex
|
||||
```
|
||||
``` -->
|
||||
|
||||
Reference in New Issue
Block a user