2412405_en-US

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

2412405_en-US

2412405_en-US

SWUpdate A/B OTA with U-Boot on i.MX8M Plus

Hi NXP Team,

I am implementing OTA on i.MX8M Plus LPDDR4 EVK using:

  • Yocto Wrynose

  • Linux 6.18.20

  • U-Boot 2026.04

  • SWUpdate 2026.05.1

Current Progress

  • SWUpdate integrated successfully into Yocto.

  • Successfully generated .swu packages.

  • SWUpdate package installation is working.

  • Hardware compatibility checking is working.

  • Successfully updated /etc/ota-version using SWUpdate.

  • rawfile handler is working.

  • Now I want to implement production-level A/B OTA with automatic rollback and signed updates.

Questions

Could you please guide me on the recommended NXP approach for:

  1. A/B rootfs partition layout.

  2. U-Boot bootcount/bootlimit based rollback.

  3. SWUpdate integration with U-Boot environment.

  4. Correct fw_env.config / libubootenv configuration.

  5. Signed .swu package verification.

  6. Anti-rollback/version protection.

  7. Secure Boot + SWUpdate integration.

Currently, the OTA update completes, but SWUpdate reports:

Cannot initialize environment from /etc/fw_env.config
Cannot persistently store update state

Is there an NXP reference design, application note, or example for SWUpdate + A/B + U-Boot rollback + signed OTA on i.MX8M Plus?

Thanks.

i.MX 8M | i.MX 8M Mini | i.MX 8M NanoYocto ProjectRe: SWUpdate A/B OTA with U-Boot on i.MX8M Plus

Hello,

We do not provide a standard EVK A/B update framework out of the box. A/B update, rollback policy, and power-fail-safe boot selection are system-level features you must implement using U-Boot + SWUpdate. The closest references are:

  • AN12900 - Secure OTA prototype for Linux using CAAM and Mender or SWUpdate.
  • AN13872 - Enabling SWUpdate.
  • meta-swupdate-imx - NXP Yocto layer with SWUpdate.

Best regards.

Re: SWUpdate A/B OTA with U-Boot on i.MX8M Plus

Hey vp1,
While I do not have an exact answer, I would like to make you aware that Torizon now supports any i. MX SoCs. It's deployed in many critical i.MX8MPlus products worldwide (mostly on Toradex SoMs). It does feature highly reliable OTA (default is OSTree but can be changed) 
It includes out-of-the-box secure boot, anti-rollback, vulnerability management (for EU CRA compliance), and more. 
The OS is free and open source; we are happy to help if you like. Contact us if you like to give it a try on the i.MX8M Plus LPDDR4 EVK or your own HW.
www.torizon.io 

Sorry for the pitch, i work for Torizon and this seemed relevant. 

Re: SWUpdate A/B OTA with U-Boot on i.MX8M Plus

Thanks for the information.

I would like to get some guidance on the recommended OTA architecture for our i.MX 8M Plus evk.

For our i.MX 8M Plus evk, we need a secure OTA solution with:

  • A/B or fail-safe updates

  • Signed/authenticated OTA packages

  • Secure Boot integration

  • Anti-rollback

  • Automatic recovery after failed/power-interrupted updates

  • Key rotation/revocation

  • Preservation of device identity/configuration

  • Factory recovery and update logging

    For these requirements, could you please suggest which approach is recommended for the i.MX 8M Plus evk?

    Specifically, should we continue with the U-Boot + A/B + SWUpdate approach discussed in this thread, or would you recommend another solution such as RAUC, Mender, or an NXP-supported OTA architecture?

Tags (1)
No ratings
Version history
Last update:
2 weeks ago
Updated by: