Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
5ab9523
add MCXA577 bootloader, blinky app, and ec-slimloader-mcxa library
alamfarjadf Apr 2, 2026
e6c73e3
fix embassy dependency resolution and clippy warning
alamfarjadf Apr 2, 2026
6377471
remove load.rs from PR (kept locally, unused)
alamfarjadf Apr 2, 2026
d5f2142
Merge branch 'main' into mcxa-577-bootloader
alamfarjadf Apr 4, 2026
502cd91
git dep changes and SGI signature updates; add rustdoc comments
alamfarjadf Apr 7, 2026
e0f5580
Merge branch 'main' into mcxa-577-bootloader
alamfarjadf Apr 15, 2026
f185706
mcxa cmpa/cfpa provisioning
alamfarjadf Apr 27, 2026
13e2e38
fix STRIDE / hyenas CWE issues
alamfarjadf May 16, 2026
59d2344
Harden CMPA scratch lifecycle staging
alamfarjadf May 19, 2026
bbfa20c
Merge branch 'main' into mcxa-577-bootloader
alamfarjadf May 19, 2026
27d4f5f
Merge branch 'main' into mcxa-577-bootloader
alamfarjadf Jun 10, 2026
fb0c240
gitignore
alamfarjadf Jun 15, 2026
4a573ec
align embassy dependencies; use cortex-m reset; remove OTP ROM API fu…
alamfarjadf Jul 9, 2026
4537a8b
lifecycle provisioning updates
alamfarjadf Jul 17, 2026
b517176
provisining flow updates
alamfarjadf Jul 20, 2026
3e9eeaa
consolidate provisioning interface
alamfarjadf Jul 20, 2026
78ffbcf
jump update, use header validation; ROTKH provisioning updates
alamfarjadf Jul 25, 2026
af996ef
address NbootCtx inputs on an unprovisioned MCU
alamfarjadf Jul 30, 2026
3db3385
Add flexSPI boot config to first setup
alamfarjadf Aug 5, 2026
643c6e3
SBL first provision; cargo fmt; deny and check updates
alamfarjadf Aug 11, 2026
0001414
add missing toml files
alamfarjadf Aug 11, 2026
6746b85
security provisioning standalone cargo.toml
alamfarjadf Aug 11, 2026
ae68481
exclude MCXA from linux target in CI
alamfarjadf Aug 11, 2026
f38dd33
Update examples/mcxa-577app/app/src/main.rs
alamfarjadf Aug 13, 2026
0d2e8c0
Update app main.rs
alamfarjadf Aug 14, 2026
eea3ebe
ext-flash journal; type 3A bank swap journal; address comments
alamfarjadf Aug 18, 2026
57b2f3a
remove erroneous imxrt dep. from mcxa-provisioner
alamfarjadf Aug 18, 2026
f1f39e0
defmt and mcxa app config updates
alamfarjadf Aug 18, 2026
46f4df4
re-enable full authentication flow with EXT flash journal
alamfarjadf Aug 19, 2026
e744a64
update app memory.x and build.rs; add mcxa-memory TOML; fix provision…
alamfarjadf Aug 20, 2026
9fb2ae9
harden dev mode detection; defmt format fix
alamfarjadf Aug 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 44 additions & 5 deletions .github/workflows/check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,12 +41,18 @@ jobs:
- name: cargo fmt --check (libs)
run: cargo fmt --check
working-directory: "./libs"
- name: cargo fmt --check (examples)
- name: cargo fmt --check (examples/rt685s)
run: cargo fmt --check
working-directory: "./examples/rt685s"
- name: cargo fmt --check (examples/mcxa-577app)
run: cargo fmt --check
working-directory: "./examples/mcxa-577app"
- name: cargo fmt --check (bootloader-tool)
run: cargo fmt --check
working-directory: "./bootloader-tool"
- name: cargo fmt --check (mcxa-security-provisioning)
run: cargo fmt --check
working-directory: "./mcxa-security-provisioning"

clippy:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -78,20 +84,35 @@ jobs:
clippy_flags: -- -F clippy::suspicious -D clippy::correctness -F clippy::perf -F clippy::style
github_token: ${{ secrets.GITHUB_TOKEN }}
workdir: "./libs"
- name: cargo clippy (examples)
extra_args: --features mimxrt685s
- name: cargo clippy (examples/rt685s)
uses: giraffate/clippy-action@v1
with:
reporter: "github-pr-check"
clippy_flags: -- -F clippy::suspicious -D clippy::correctness -F clippy::perf -F clippy::style
github_token: ${{ secrets.GITHUB_TOKEN }}
workdir: "./examples/rt685s"
- name: cargo clippy (examples/mcxa-577app)
uses: giraffate/clippy-action@v1
with:
reporter: "github-pr-check"
clippy_flags: -- -F clippy::suspicious -D clippy::correctness -F clippy::perf -F clippy::style
github_token: ${{ secrets.GITHUB_TOKEN }}
workdir: "./examples/mcxa-577app"
- name: cargo clippy (bootloader-tool)
uses: giraffate/clippy-action@v1
with:
reporter: "github-pr-check"
clippy_flags: -- -D clippy::suspicious -D clippy::correctness -D clippy::perf -D clippy::style
github_token: ${{ secrets.GITHUB_TOKEN }}
workdir: "./bootloader-tool"
- name: cargo clippy (mcxa-security-provisioning)
uses: giraffate/clippy-action@v1
with:
reporter: "github-pr-check"
clippy_flags: -- -F clippy::suspicious -D clippy::correctness -F clippy::perf -F clippy::style
github_token: ${{ secrets.GITHUB_TOKEN }}
workdir: "./mcxa-security-provisioning"

# Enable once we have a released crate
# semver:
Expand Down Expand Up @@ -135,7 +156,7 @@ jobs:
working-directory: "./libs"
env:
RUSTDOCFLAGS: --cfg docsrs
- name: cargo doc (examples)
- name: cargo doc (examples/rt685s)
run: cargo doc --no-deps
working-directory: "./examples/rt685s"
env:
Expand Down Expand Up @@ -197,12 +218,24 @@ jobs:
log-level: warn
manifest-path: ./libs/Cargo.toml
command: check
- name: Cargo deny (examples)
- name: Cargo deny (examples/rt685s)
uses: EmbarkStudios/cargo-deny-action@v2
with:
log-level: warn
manifest-path: ./examples/rt685s/Cargo.toml
command: check
- name: Cargo deny (examples/mcxa-577app)
uses: EmbarkStudios/cargo-deny-action@v2
with:
log-level: warn
manifest-path: ./examples/mcxa-577app/Cargo.toml
command: check
- name: Cargo deny (mcxa-security-provisioning)
uses: EmbarkStudios/cargo-deny-action@v2
with:
log-level: warn
manifest-path: ./mcxa-security-provisioning/Cargo.toml
command: check

msrv:
# check that we can build using the minimal rust version that is specified by this crate
Expand Down Expand Up @@ -233,12 +266,18 @@ jobs:
- name: cargo +${{ matrix.msrv }} check (libs)
run: cargo check --features mimxrt685s
working-directory: "./libs"
- name: cargo +${{ matrix.msrv }} check (examples)
- name: cargo +${{ matrix.msrv }} check (examples/rt685s)
run: cargo check
working-directory: "./examples/rt685s"
- name: cargo +${{ matrix.msrv }} check (examples/mcxa-577app)
run: cargo check
working-directory: "./examples/mcxa-577app"
- name: cargo +${{ matrix.msrv }} check (bootloader-tool)
run: cargo check
working-directory: "./bootloader-tool"
- name: cargo +${{ matrix.msrv }} check (mcxa-security-provisioning)
run: cargo check
working-directory: "./mcxa-security-provisioning"

fuzz:
runs-on: ubuntu-latest
Expand Down
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# Rust build artifacts
target/
1 change: 1 addition & 0 deletions deny.toml
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,7 @@ allow = [
"MIT",
"Apache-2.0",
"Unicode-3.0",
"BSD-3-Clause",
#"Apache-2.0 WITH LLVM-exception",
]
# The confidence threshold for detecting a license from license text.
Expand Down
21 changes: 21 additions & 0 deletions examples/mcxa-577app/.cargo/config.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
[build]
target = "thumbv8m.main-none-eabihf"

# Runner for app and bootloader. Provisioner overrides this in its own config.
[target.thumbv8m.main-none-eabihf]
runner = "probe-rs run --chip MCXA577 --speed 10000"

# Flags for all workspace members (app, bootloader).
# The provisioner sub-workspace uses RUSTFLAGS in its [env] to override this
# set and exclude -Tdefmt.x, since it uses log/rtt-target instead of defmt.
[target.'cfg(all(target_arch = "arm", target_os = "none"))']
rustflags = [
"-C", "linker=flip-link",
"-C", "link-arg=-Tlink.x",
"-C", "link-arg=-Tdefmt.x",
"-C", "link-arg=--nmagic",
"-C", "force-frame-pointers=yes",
]

[env]
DEFMT_LOG = "trace"
42 changes: 42 additions & 0 deletions examples/mcxa-577app/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
[workspace]
resolver = "2"
members = [
"app",
"bootloader",
]

[workspace.package]
version = "0.1.0"
edition = "2021"
license = "MIT OR Apache-2.0"
repository = "https://github.com/OpenDevicePartnership/ec-slimloader"

[workspace.dependencies]
heapless = "0.8"
partition-manager = { git = "https://github.com/OpenDevicePartnership/embedded-services.git", tag = "v0.1.0", default-features = false }
partition-manager-macros = { git = "https://github.com/OpenDevicePartnership/embedded-services.git", tag = "v0.1.0" }
static_cell = "2.1"
embassy-sync = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-mcxa = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0", default-features = false }
embassy-executor = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0", default-features = false }
embassy-time = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }

[patch.crates-io]
embassy-embedded-hal = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-executor = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-executor-macros = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-futures = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-hal-internal = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-sync = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-time = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-time-driver = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
embassy-time-queue-utils = { git = "https://github.com/embassy-rs/embassy", rev = "f21d63db2d104a3b4c070408e529c109a64e65b0" }
Comment on lines +19 to +33

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These should used released versions of embassy (when available, so only mcxa should be a git dep)


[profile.dev]
panic = "abort"

[profile.release]
debug = 2
lto = false
opt-level = 2
panic = "abort"
21 changes: 21 additions & 0 deletions examples/mcxa-577app/app/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
[package]
name = "mcxa-577app"
version = "0.1.0"
edition = "2021"
license.workspace = true

[dependencies]
cortex-m = { version = "0.7", features = ["critical-section-single-core"] }
cortex-m-rt = { version = "0.7", features = ["set-sp", "set-vtor"] }
defmt = "1.0"
defmt-rtt = "1.0"
embassy-mcxa = { workspace = true, features = ["rt", "defmt", "mcxa5xx"] }
embassy-executor = { workspace = true, features = ["platform-cortex-m", "executor-thread"] }
embassy-time = { workspace = true, features = ["defmt", "defmt-timestamp-uptime"] }
panic-probe = { version = "1.0", features = ["print-defmt"] }
Comment on lines +8 to +15

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to be more consistent. Use the workspace or don't.


[[bin]]
name = "app"
path = "src/main.rs"


17 changes: 17 additions & 0 deletions examples/mcxa-577app/app/build.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
use std::env;
use std::fs::File;
use std::io::Write;
use std::path::PathBuf;

fn main() {
// Put `memory.x` in our output directory and ensure it's
// on the linker search path.
let out = &PathBuf::from(env::var_os("OUT_DIR").unwrap());
File::create(out.join("memory.x"))
.unwrap()
.write_all(include_bytes!("memory.x"))
.unwrap();
println!("cargo:rustc-link-search={}", out.display());

println!("cargo:rerun-if-changed=memory.x");
}
21 changes: 21 additions & 0 deletions examples/mcxa-577app/app/memory.x
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MEMORY
{
/* MCXA577 app memory map */
/* NOTE 1 K = 1 KiBi = 1024 bytes */
/* Bootloader uses 0x0000_0000..0x0000_FFFF (64KiB). App starts at slot_a = 0x0001_0000. */
FLASH (rx) : ORIGIN = 0x00010000, LENGTH = 0x00019000 /* section 1: 100KB */
FLASH1 (rx) : ORIGIN = 0x00180000, LENGTH = 0x00019000 /* section 2: ~1.5MB offset, 100KB */
RAM (rwx) : ORIGIN = 0x20000000, LENGTH = 64K
}

/* Stack grows down from end of RAM */
_stack_start = ORIGIN(RAM) + LENGTH(RAM);

/* Extra linker section for code placed in FLASH1 (~1.5MB offset).
* Functions annotated with #[link_section = ".text_flash1"] will land here.
*/
SECTIONS {
.text_flash1 : ALIGN(4) {
*(.text_flash1 .text_flash1.*)
} > FLASH1
} INSERT AFTER .text;
91 changes: 91 additions & 0 deletions examples/mcxa-577app/app/src/main.rs

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems to me that this app should be "complete". That is, it should open the journal and mark it Confirmed. Examples set the patterns folks will end up using.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good call, I will add this.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All the examples should follow the same names. So this example should be called examples/mcxa-577/application and the bootloader should be examples/mcxa-577/bootloader

Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
#![no_std]
#![no_main]

use defmt_rtt as _;
use embassy_executor::Spawner;
use embassy_mcxa as hal;
use embassy_time::Timer;
use hal::bind_interrupts;
use hal::dma::DmaChannel;
use hal::gpio::{DriveStrength, Level, Output, SlewRate};
use hal::peripherals::SGI0;
use hal::sgi::hash::HashSize;
use hal::sgi::{InterruptHandler, Sgi};
use panic_probe as _;

bind_interrupts!(struct Irqs {
SGI => InterruptHandler<SGI0>;
});

#[embassy_executor::main]
async fn main(_spawner: Spawner) {
let mut p = hal::init(hal::config::Config::default());

defmt::info!("Blinky example with a sprinkle of SGI hashing");

let mut dma_ch0 = DmaChannel::new(p.DMA0_CH0.reborrow());
let mut hash_result = [0u8; 48];
let input_data: [u8; 256] = core::array::from_fn(|i| i as u8);

let mut sgi = Sgi::new(p.SGI0.reborrow(), Irqs).unwrap();
match sgi
.sha2_start_and_finalize(&mut dma_ch0, HashSize::Sha384, &input_data, &mut hash_result)
.await
{
Ok(()) => defmt::info!("DMA hash: {=[u8]:x}", &hash_result[..]),
Err(e) => defmt::error!("DMA hash failed: {:?}", defmt::Debug2Format(&e)),
}

let mut red = Output::new(p.P2_14, Level::High, DriveStrength::Normal, SlewRate::Fast);
let mut green = Output::new(p.P2_22, Level::High, DriveStrength::Normal, SlewRate::Fast);
let mut blue = Output::new(p.P2_23, Level::High, DriveStrength::Normal, SlewRate::Fast);

let mut rate = 250;

defmt::info!("It's showtime...");

for _ in 0..10 {
if rate > 1000 {
rate = 250;
}
red.toggle();
Timer::after_millis(rate).await;

red.toggle();
green.toggle();
Timer::after_millis(rate).await;

green.toggle();
blue.toggle();
Timer::after_millis(rate).await;
blue.toggle();

Timer::after_millis(rate).await;
rate = rate.wrapping_add(100);
}

defmt::info!("10 blink cycles done - jumping to FLASH1");
flash1_pattern(&mut red, &mut green, &mut blue).await;
}

/// Runs from FLASH1 (~1.5MB offset). All three LEDs pulse together, white,
/// distinct from section 1's sequential RGB pattern.
#[link_section = ".text_flash1"]
#[inline(never)]
async fn flash1_pattern(

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Have you checked where this is actually placed? In the memory.x there's no section defined with this name, so it's not clear to me this actually works.

I tried compiling the example to check myself, but it doesn't compile. The security provisioning crate is broken and even then there's stuff missing like a flash1.x file and the partition manager setup.

red: &mut hal::gpio::Output<'_>,
green: &mut hal::gpio::Output<'_>,
blue: &mut hal::gpio::Output<'_>,
) {
defmt::info!("Running from FLASH1");
loop {
red.set_low();
green.set_low();
blue.set_low();
Timer::after_millis(1000).await;
red.set_high();
green.set_high();
blue.set_high();
Timer::after_millis(1000).await;
}
}
39 changes: 39 additions & 0 deletions examples/mcxa-577app/bootloader/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
[package]
name = "mcxa-577app-bootloader"
version = "0.1.0"
edition = "2021"
license.workspace = true

[features]
default = ["defmt", "certificate-logging", "verification-logging", "mcxa"]
defmt = ["dep:defmt", "dep:defmt-or-log", "dep:defmt-rtt", "defmt-or-log/defmt"]
log = ["dep:defmt-or-log", "defmt-or-log/log"]
mcxa = ["ec-slimloader-mcxa/mcxa5xx"]
mcxa5xxevk = ["ec-slimloader-mcxa/mcxa5xxevk"]
certificate-logging = ["ec-slimloader-mcxa/certificate-logging"]
verification-logging = ["ec-slimloader-mcxa/verification-logging"]

[[bin]]
name = "bootloader"
path = "src/main.rs"

[dependencies]
cortex-m = { version = "0.7", features = ["critical-section-single-core"], default-features = false }
cortex-m-rt = "0.7"
defmt = { version = "1.0", optional = true }
defmt-or-log = { version = "0.2.3", optional = true }
defmt-rtt = { version = "1.0", optional = true }
panic-probe = { version = "1.0", features = ["print-defmt"] }

heapless = { version = "0.8", default-features = false }
partition-manager = { workspace = true, features = ["macros"] }
partition-manager-macros = { workspace = true }
embassy-sync = { workspace = true }

ec-slimloader-mcxa = { path = "../../../libs/ec-slimloader-mcxa", default-features = false, features = ["mcxa5xx", "defmt"] }
ec-slimloader = { path = "../../../libs/ec-slimloader", default-features = false }
ec-slimloader-state = { path = "../../../libs/ec-slimloader-state", default-features = false }
mcxa-security-provisioning = { path = "../../../mcxa-security-provisioning", default-features = false, features = ["defmt"] }

embassy-mcxa = { workspace = true, features = ["rt", "mcxa5xx"] }
embassy-executor = { workspace = true, features = ["platform-cortex-m", "executor-thread"] }
Loading
Loading