Unit content
Bootloaders and firmware updates
A bootloader is a small program that runs before the main firmware and decides which application image to start.
Besides ordinary startup, a bootloader can support firmware updates by receiving or locating a new image, checking that it is structurally valid, writing it to nonvolatile memory and then transferring control to its entry point.
An update must remain recoverable if power is lost or the new image fails to boot. One strategy keeps two image slots: write the new image into the inactive slot, verify it, try it, and mark it accepted only after successful startup. The previous image remains available for rollback until that point.
Image metadata can include target identity, version, size and an integrity check. Systems with an adversarial threat model also need authenticity, not merely accidental-corruption detection.
The bootloader and application must agree on memory regions and handoff conventions. Updating one must not overwrite data still needed to recover.
Reliable firmware update is therefore a transactional change to nonvolatile executable state: either a valid image becomes bootable, or the device retains a known recovery path.