Hi Frank,

On Thu, Jan 22, 2015 at 10:52:36AM +0100, Frank wrote:
> Am 22.01.2015 um 10:50 schrieb Ludwig Ortmann:
> > On Thu, Jan 22, 2015 at 10:20:47AM +0100, Frank wrote:
> >> it's possible to brick the device when flash code crashes every time
> >> when it writes a new image. Then we have an corrupt image and an non
> >> working image.
> > I have trouble making sense of this - could you please elaborate a
> > bit? (This is what I read: "If there is an error in the firmware update
> > code it might not work.")
> This is what i mean.

OK, but (quoting more from the original mail):

> > To recover from this point i think it's sufficient implementing an
> > simple low level broadcast receiver without cryptographic checks or
> > an network stack. Alternatively there is space needed for an third
> > firmware image.

How would adding a second flashing mechanism help with this
problem? My fear so far is that throwing more code at this problem
will only deplete memory and introduce new errors.

I'd rather have a thoroughly tested and well designed implementation
in the first place ;)

Also, what would the third image change?

Cheers, Ludwig
_______________________________________________
devel mailing list
[email protected]
http://lists.riot-os.org/mailman/listinfo/devel

Reply via email to