Recover from Hard fault after executing dynamic code.
I have developed a dynamic loader that works in an STM32 (cortex-m4) microcontroller. Basically, the base firmware is in charge of writing new dynamic code into flash, and executing it. It works as expected. but I am trying to make the execution of the dynamic code as safe as possible. At the moment I am not thinking about malicious code from an attacker as this relates more to the security of the system.
I am more concerned that for some reason, someone who has loadedDynamic Code did not test it extensively and might create a hard fault. Is it possible to implement a monitor that detects if the hard fault handler was caused during executing of the dynamic code (e.g. setting a flag when executing the code) and re-write the dynamic code in flash so next time the MCU is rebooted the code is not executed again.
Would this approach be viable or has someone had any experience on scenarios where the base firmware must be able to recover from hard faults caused by external unknown bugs (in this case from loading dynamic code).
