My design executes entirely out of RAM, fetching the binary at IPL (so the "boot rom" has fixed/unevolving responsibilities -- get it right first time)
I am strongly tempted to *prohibit* updates to it after deployment as that just seems like another opportunity for feeping creaturism and the potential for bricking devices (though, for the life of me, I can't see how FLASH updates should *ever* be capable of that sort of outcome, if designed properly!)
Are there any reasons I might *want* to leave that door open?