What a Cortex-M core does before your first instruction
Sample article. Replace it with your own content, or edit it and keep it.
When reset is released, an ARMv7-M core (Cortex-M3/M4/M7) does not run any software to find its first instruction. The architecture defines this behaviour:
SP_mainis loaded from vector table entry 0.PCis loaded from vector table entry 1 (the reset vector). Bit 0 must be1to show Thumb state; it is cleared fromPCand setsEPSR.T.- Execution starts at that address.
Where is the vector table at reset?
The vector table is at the address held in VTOR. What VTOR holds at reset
depends on the core:
| Core | VTOR at reset |
|---|---|
| Cortex-M3 / M4 | 0x00000000 (fixed) |
| Cortex-M7 | Set by the INITVTOR input chosen by the SoC designer |
| Cortex-M23 / M33 | INITSVTOR / INITNSVTOR inputs |
So on a Cortex-M4, whatever memory the SoC decodes at address 0x0 supplies
the first two words. That could be a boot ROM, flash, or an aliased region.
Why this matters in validation
- A corrupt word at entry 0 or 1 gives a lockup or HardFault before any of your
code runs. In lockup the debugger shows
PC = 0xEFFFFFFE(the architectural lockup address) andDHCSR.S_LOCKUPis set. - If the device has a boot ROM, it runs first and then passes control to your
image by writing
VTOR, loadingMSP, and branching to your reset vector.
Always check this against the device datasheet and the ARMv7-M Architecture Reference Manual.