NOR update with customized trusted image

< How to manage OpenSTLinux projects in STM32CubeIDE
Applicable for STM32MP15x lines

This article explains how to update the bootloader objects of the NOR memory, located on the STM32MP157x-EV1 Evaluation board More info green.png, using STM32CubeIDE.

BackToNavigationTree button.png

1 Overview[edit]

The different steps to update a NOR memory with a customized trusted image are the following ones:

  • Initialize the NOR memory with the Starter Package image by means of the STM32CubeProgrammer
  • Within STM32CubeIDE:
    • customize the trusted image, using the device trees generated by the embedded STM32CubeMX
    • compile the corresponding Linux® device tree and bootloader images
    • update them on the running STM32MP157x-EV1 Evaluation board More info green.png
  • Check that the new customization is correctly set up


The NOR memory contains only the TF-A BL2 and FIP partitions. The Linux® partitions are located in the SD™ card.
All those steps are explained in the chapters below.

2 Initialize the NOR memory with the Starter Package[edit]

Initialize the NOR memory with the Starter Package image with STM32CubeProgrammer.
For that purpose, select the Starter package corresponding to the targeted STM32MP157x-EV1 Evaluation board More info green.png and jump to chapter Downloading the image and flashing it on the board.

Before executing the next step, check the bootloader version, which is visible in boot messages:

  • TF-A BL2 version, booting from the NOR memory
NOR initial setting: TF-A BL2 version


  • U-boot version and extlinux.conf file used, booting from the NOR memory
NOR initial setting: U-boot version & extlinux.conf


  • extlinux.conf content before update
NOR initial setting: extlinux.conf content

3 Customize and update bootloader images on the running STM32MP157x-EV1 More info green.png board[edit]

3.1 Build the trusted image inside STM32CubeIDE with the new expected device trees[edit]

After the customization of hardware resources within the embedded STM32CubeMX, new device trees for Linux® and for the bootloader are generated.
The next step is to build an update of the new trusted image; this is covered also within STM32CubeIDE with:

Note that for Linux®, only the device tree needs to be updated as described hereafter.

3.2 STM32MP157x-EV1 More info green.png board update with new Linux® device tree[edit]

In this step, the STM32MP157x-EV1 Evaluation board More info green.png is up and running with network access: target status is green. After having compiled the device tree generated by STM32CubeMX, you must:

  • update the STM32MP15x target bootfs with the new .dtb under /boot
  • and adjust /boot/mmc0_extlinux/extlinux.conf to declare the new device tree and set it as default. Note that this setup is done in the SD™ card memory since the Linux® partitions are located there.

For that purpose, follow the steps explained below:

  • select the Cortex-A Linux® Deployment shortcut configuration available from Linux® project Run As... menu.
Linux® deployment configuration


  • Validate your choice and use the Run button. You get in a dedicated Linux® Deployment console a message like this one:
NOR Linux® deployment message


  • Check extlinux.conf content after the NOR Linux® device tree update (DEFAULT and LABEL have changed)
NOR Linux® device tree update


3.3 STM32MP157x-EV1 More info green.png board update with new bootloader images[edit]

In this step, the STM32MP157x-EV1 Evaluation board More info green.png is up and running with network access: target status is green.
After having built customized bootloader images, you must update the STM32MP157x-EV1 Evaluation board More info green.png.

  • Select the Cortex-A project in STM32CubeIDE and right-click to get the Cortex-A Bootloader Deployment shortcut.
Bootloader update shortcut


The connection is automatically set and you need to scan the STM32MP15x target storage, using the Scan... button.
This storage list depends on the board and on the boot storage used.

Then, select the storage to update (NOR #0 here), and the TF-A BL2 and FIP image to update from FIP_artifacts/.
Here is the corresponding STM32 Cortex-A Bootloader Deployment configuration:

NOR Bootloader deployment configuration


  • Click on Run. You get in a dedicated Bootloader Deployment console the following message:
NOR Bootloader deployment message


4 Check the new bootloader version after the customization with STM32CubeIDE[edit]

After the update, the new bootloader version can be checked by comparing the versions appearing in boot messages: the TF-A BL2 and U-Boot versions are modified and Linux® uses the generated device tree.
Here are the new boot messages:

  • TF-A BL2 updated version, booting from the NOR memory
NOR updated TF-A BL2 version


  • U-Boot updated version and Linux® device tree, booting from the NOR memory
NOR updated U-Boot version & Linux® device tree


BackToNavigationTree button.png