Skip to content

Commit 96e3500

Browse files
committed
docs: migration-guide-4.3: Add TF-M sign note
Add a note about BL2 (MCUboot) signing updates when the board is built as TF-M NS. Signed-off-by: BUDKE Gerson Fernando <gerson.budke@leica-geosystems.com>
1 parent 69026e3 commit 96e3500

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed

doc/releases/migration-guide-4.3.rst

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -427,5 +427,26 @@ LED Strip
427427

428428
* Renamed ``arduino,modulino-smartleds`` to :dtcompatible:`arduino,modulino-pixels`
429429

430+
Trusted Firmware-M
431+
==================
432+
433+
* The signing process for BL2 (MCUboot) was updated. The boards that run using
434+
TF-M NS and require BL2 must have their flash layout with the flash controller
435+
information. This will ensure that when signing the hex/bin files all the
436+
details will be present in the S and NS images. The image now has the details
437+
to allow the FWU state machine be correct and allow FOTA.
438+
(:github:`94470`)
439+
440+
* The ``--align`` parameter was fixed to 1. Now, it's set to the flash DT ``write_block_size``
441+
property, but still provides 1 as a fallback for specific vendors.
442+
* The ``--max-sectors`` value is now calculated based on the number of images, taking into
443+
consideration the largest image size.
444+
* The ``--confirm`` option now confirms both S and NS HEX images, ensuring that any image
445+
that runs is valid for production and development.
446+
* S and NS BIN images are now available. These are the correct images to be used in FOTA. Note
447+
that S and NS images are unconfirmed by default, and the application is responsible for
448+
confirming them with ``psa_fwu_accept()``. Otherwise, the images will roll back on the next
449+
reboot.
450+
430451
Architectures
431452
*************

0 commit comments

Comments
 (0)