48 lines
2.8 KiB
Markdown
48 lines
2.8 KiB
Markdown
# STM32G474xB USB boot port
|
|
|
|
SET v2 USB CDC bootloader for STM32G474 with 128 KiB Flash. Uses HSI16 for
|
|
the CPU and HSI48 with CRS USB SOF synchronization for USB; no HSE required.
|
|
Dedicated USB pins: PA11/PA12. The board must supply VDDUSB correctly.
|
|
|
|
Compile the shared `src/set_protocol.c`, `src/set_firmware.c`, `src/set_boot.c`,
|
|
this port's `boot_main.c`, `boot_flash.c`, `boot_request.c`, `boot_usb_stream.c`
|
|
and `boot_usb_port.c`. Supply G4 CMSIS/HAL/startup, ST USB Device CDC and the
|
|
board's CDC byte transport (`usb_cdc.h`, `usb_setp_stream.h`).
|
|
Copy `boot_config.template.h` as `boot_config.h`. The wrapper uses the common
|
|
`../stm32-usb-boot/boot_usb_protocol.inc`; retain that directory when importing.
|
|
|
|
For the shared emulator CDC transport, set `EMU_USB_SET_V2=1`,
|
|
`USB_CDC_IRQn=USB_LP_IRQn` and optionally `USB_CDC_PRODUCT_NAME`.
|
|
Provide `usbd_conf.h` using `stm32g4xx_hal.h`. The low-level port allocates
|
|
non-overlapping PMA buffers for EP0, CDC IN/OUT and notifications.
|
|
|
|
Link boot code below `0x0800F000`, reserve `0x0800F000..0x0800FFFF` for metadata,
|
|
and link the application at `0x08010000` with VTOR at that address.
|
|
Application capacity is 64 KiB, ending at `0x08020000` (exclusive).
|
|
Flash size must be 128 KiB and DBANK must be zero (single bank, 4 KiB pages).
|
|
BFB2 and FB_MODE bank swapping must be disabled. Unsupported geometry is
|
|
rejected before erase. On xB in dual-bank mode the upper 64 KiB starts at
|
|
`0x08040000`, leaving a hole at the application's link address. Therefore this
|
|
profile deliberately rejects dual-bank mode. Set DBANK=0 via SWD before the
|
|
initial installation, then program both bootloader and application afresh.
|
|
The port does not modify Option Bytes.
|
|
|
|
HAL doubleword programming plus an eight-byte staging buffer handles arbitrary
|
|
SET block sizes without programming ECC words twice. Only the final word is
|
|
padded with FF; CRC covers the declared image size. END checks written Flash
|
|
and vectors, commits metadata last; ACTIVATE defers reset by 500 ms for the reply.
|
|
|
|
The reset policy matches F407: valid vectors alone allow SWD-installed images.
|
|
Metadata is not required at reset, so an incomplete image with valid vectors can
|
|
also start after an interrupted update. Erase the first application page through
|
|
SWD to recover. No rollback, resume or signature authentication is implemented.
|
|
|
|
Application integration: compile `boot_request.c`, reserve `TAMP->BKP0R`, call
|
|
`g474_request_boot(now)` for an update request and `g474_reset_poll(now)` from
|
|
the main loop. Reset consumes and clears the backup-register request.
|
|
|
|
Host test `test_boot_port.c` covers the 64 KiB slot boundaries, geometry rejection, vector validation,
|
|
every block size 1..256, all final-word tails, sequential offsets and failures.
|
|
Compile it with this directory and `../../include` on the include path.
|
|
Hardware USB/Flash/power-loss tests remain required on the target board.
|