still some bugs, though by setting pll mult -> br of 115200
[my-code/arm.git] / betty / lpcload.c
1 /*
2  * lpcload.c - load firmware into ram of lpc2220 via uart0
3  *
4  * author: hackbard@hackdaworld.org, rolf.anders@physik.uni-augsburg.de
5  *
6  * build: make
7  * usage: sudo ./lpcload -d /dev/ttyS0 -f firmware.hex [-v]
8  */
9
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include <string.h>
13 #include <unistd.h>
14 #include <sys/types.h>
15 #include <sys/stat.h>
16 #include <fcntl.h>
17 #include <termios.h>
18
19 #define VERBOSE                 (1<<0)
20 #define FIRMWARE                (1<<1)
21 #define BANK0                   (1<<2)
22 #define BANK2                   (1<<3)
23 #define BL                      (1<<4)
24
25 #define BANK0_ADDR              0x80000000
26 #define BANK2_ADDR              0x82000000
27 #define BANK_SIZE               0x00100000
28 #define BL_ADDR                 0x7fffe000
29 #define BL_SIZE                 0x00002000
30
31 #define CMD_READ                'R'             // stay compatible to fwflash!
32
33 #define TXRX_TYPE_SYNC          0x00
34 #define TXRX_TYPE_CKSM          0x00
35 #define TXRX_TYPE_BAUD          0x01
36 #define TXRX_TYPE_CMD           0x02
37 #define TXRX_TYPE_DATA          0x03
38 #define TXRX_TYPE_GO            0x04
39
40 #define CMD_SUCCESS             "0\r\n"
41 #define INVALID_COMMAND         "1\r\n"
42 #define SRC_ADDR_ERROR          "2\r\n"
43 #define DST_ADDR_ERROR          "3\r\n"
44 #define SRC_ADDR_NOT_MAPPED     "4\r\n"
45 #define DST_ADDR_NOT_MAPPED     "5\r\n"
46 #define COUNT_ERROR             "6\r\n"
47 #define COMPARE_ERROR           "10\r\n"
48 #define BUSY                    "11\r\n"
49 #define PARAM_ERROR             "12\r\n"
50 #define ADDR_ERROR              "13\r\n"
51 #define ADDR_NOT_MAPPED         "14\r\n"
52 #define CMD_LOCKED              "15\r\n"
53 #define INVALID_CODE            "16\r\n"
54 #define INVALID_BAUD_RATE       "17\r\n"
55 #define INVALID_STOP_BIT        "18\r\n"
56
57 #define CRYSTFREQ               "10000"
58 #define RAMOFFSET               0x40000200
59
60 #define BUFSIZE                 128
61
62 typedef unsigned char u8;
63 typedef unsigned short u16;
64 typedef unsigned int u32;
65
66 typedef struct s_lpc {
67         int sfd;                /* serial fd */
68         char sdev[128];         /* seriel device */
69         int fwfd;               /* fimrware fd */
70         char fwfile[128];       /* firmware file */
71         u8 info;                /* info/mode */
72         char freq[8];           /* frequency */
73         char bank0[127];        /* flash dump bank0 */
74         int b0fd;               /* dumpfile fd bank0 */
75         char bank2[127];        /* flash dump bank2 */
76         int b2fd;               /* dumpfile fd bank0 */
77         char bl[127];           /* flash dump bootloader */
78         int blfd;               /* dumpfile fd bootloader */
79         u32 roff;               /* ram offset of uc */
80         u32 jaddr;              /* addr for the jump */
81 } t_lpc;
82
83 void usage(void) {
84
85         printf("possible argv:\n");
86         printf("  -d  <serial device>\n");
87         printf("  -f  <firmware>\n");
88         printf("  -c  <crystal freq>\n");
89         printf("  -Dx <filename>\n");
90         printf("      x=0: bank0, x=2: bank2, x=b: bootloader\n");
91         printf("  -v\n");
92
93 }
94
95 int open_serial_device(t_lpc *lpc) {
96
97         struct termios term;
98
99         //memset(&term,0,sizeof(struct termios));
100
101         /* open serial device */
102
103         lpc->sfd=open(lpc->sdev,O_RDWR);
104         if(lpc->sfd<0) {
105                 perror("tts open");
106                 return lpc->sfd;
107         }
108
109         /* configure the serial device */
110
111         tcgetattr(lpc->sfd,&term);
112
113         // input/output baudrate
114
115         cfsetispeed(&term,B38400);
116         cfsetospeed(&term,B38400);
117
118         // control options -> 8n1
119
120         term.c_cflag&=~PARENB;  // no parity
121         term.c_cflag&=~CSTOPB;  // only 1 stop bit
122         term.c_cflag&=~CSIZE;   // no bit mask for data bits
123         term.c_cflag|=CS8;      // 8 data bits
124
125         // line options -> raw input
126         
127         term.c_lflag&=~(ICANON|ECHO|ECHOE|ISIG);
128
129         // input options -> enable flow control
130         
131         term.c_iflag&=~(INLCR|ICRNL|IXANY);
132         term.c_iflag|=(IXON|IXOFF);
133         
134         // output options
135
136         term.c_oflag=0;
137
138         // more control options -> timeout / flow control
139         
140         term.c_cc[VMIN]=0;
141         term.c_cc[VTIME]=20;    // 2 seconds timeout
142         //term.c_cc[VSTART]=0x11;
143         //term.c_cc[VSTOP]=0x13;
144
145         tcsetattr(lpc->sfd,TCSANOW,&term);
146
147         return lpc->sfd;
148 }
149
150 int reconfig_serial_device(t_lpc *lpc) {
151
152         struct termios term;
153         int ret;
154
155         /* reconfigure the serial device for our lousy loader tool */
156
157         tcgetattr(lpc->sfd,&term);
158
159         // disable flow control
160         
161         term.c_iflag&=~(IXON|IXOFF|IXANY|INLCR|ICRNL);
162
163         // change baudrate
164
165         cfsetispeed(&term,B115200);
166         cfsetospeed(&term,B115200);
167
168         ret=tcsetattr(lpc->sfd,TCSANOW,&term);
169
170         return ret;
171 }
172
173 int open_firmware(t_lpc *lpc) {
174
175         /* open firmware file */
176
177         lpc->fwfd=open(lpc->fwfile,O_RDONLY);
178
179         if(lpc->fwfd<0)
180                 perror("fw open");
181
182         return lpc->fwfd;
183 }
184
185 int open_dumpfiles(t_lpc *lpc) {
186
187         /* open dumpfiles */
188
189         if(lpc->info&BANK0) {
190                 lpc->b0fd=open(lpc->bank0,O_WRONLY|O_CREAT);
191                 if(lpc->b0fd<0) {
192                         perror("bank0 dump file open");
193                         return lpc->b0fd;
194                 }
195         }
196
197         if(lpc->info&BANK2) {
198                 lpc->b2fd=open(lpc->bank2,O_WRONLY|O_CREAT);
199                 if(lpc->b2fd<0) {
200                         perror("bank2 dump file open");
201                         return lpc->b2fd;
202                 }
203         }
204
205         if(lpc->info&BL) {
206                 lpc->blfd=open(lpc->bl,O_WRONLY|O_CREAT);
207                 if(lpc->blfd<0) {
208                         perror("bootloader dump file open");
209                         return lpc->blfd;
210                 }
211         }
212
213         return 0;
214
215 }
216 int txrx(t_lpc *lpc,char *buf,int len,u8 type) {
217
218         int ret,cnt;
219         int i;
220
221         /* write */
222
223         if(lpc->info&VERBOSE)
224                 printf("  >> ");
225         cnt=0;
226         while(len) {
227                 ret=write(lpc->sfd,buf+cnt,len);
228                 if(ret<0) {
229                         perror("txrx write");
230                         return ret;
231                 }
232                 if(lpc->info&VERBOSE)
233                         for(i=0;i<ret;i++)
234                                 printf("%c",
235                                        ((buf[cnt+i]>0x19)&(buf[cnt+i]<0x7f))?
236                                        buf[cnt+i]:'.');
237                 len-=ret;
238                 cnt+=ret;
239         }
240         if(lpc->info&VERBOSE) {
241                 printf(" | ");
242                 for(i=0;i<cnt;i++)
243                         printf("%02x ",buf[i]);
244                 printf("| (%d)\n",cnt);
245         }
246
247
248
249         /* cut the echo if not of type auto baud */
250
251         if(type!=TXRX_TYPE_BAUD) {
252                 while(cnt) {
253                         ret=read(lpc->sfd,buf,cnt);
254                         if(ret<0) {
255                                 perror("txrx echo cut");
256                                 return ret;
257                         }
258                         cnt-=ret;
259                 }
260         }
261
262         /* return if type is go */
263
264         if(type==TXRX_TYPE_GO)
265                 return cnt;
266
267         /* return here if type is data */
268
269         if(type==TXRX_TYPE_DATA)
270                 return cnt;
271
272         /* read */
273
274         ret=read(lpc->sfd,buf,1);
275         if(ret<0) {
276                 perror("txrx read (first byte)");
277                 return ret;
278         }
279                 
280         switch(buf[0]) {
281                 case 'S':
282                         cnt=13;
283                         break;
284                 case 'O':
285                         cnt=3;
286                         break;
287                 case 'R':
288                         cnt=7;
289                         break;
290                 case '0':
291                         cnt=2;
292                         break;
293                 default:
294                         printf("txrx read: bad return byte '%02x'\n",buf[0]);
295                         break;
296         }
297
298         ret=1;
299         i=cnt;
300         while(i) {
301                 ret=read(lpc->sfd,buf+1+cnt-i,i);
302                 if(ret<0) {
303                         perror("txrx read (next bytes)");
304                         return ret;
305                 }
306                 i-=ret;
307         }
308         if(lpc->info&VERBOSE) {
309                 printf("  << ");
310                 for(i=0;i<cnt+1;i++)
311                         printf("%c",((buf[i]>0x19)&(buf[i]<0x7f))?
312                                     buf[i]:'.');
313                 printf(" | ");
314                 for(i=0;i<cnt+1;i++)
315                         printf("%02x ",buf[i]);
316                 printf("| (%d)\n",cnt+1);
317         }
318         buf[cnt+1]='\0';
319
320         /* check/strip return code if type is cmd */
321
322         if(type==TXRX_TYPE_CMD) {
323                 ret=strlen(CMD_SUCCESS);
324                 if(!strncmp(buf,CMD_SUCCESS,ret)) {
325                         for(i=ret;i<cnt;i++)
326                                 buf[i-ret]=buf[i];
327                         buf[cnt]='\0';
328                 }
329                 else {
330                         printf("txrx bad return code!\n");
331                         return -1;
332                 }
333         }
334
335         return cnt;
336 }
337
338 int bl_init(t_lpc *lpc) {
339
340         char buf[BUFSIZE];
341         int len;
342
343         /* auto baud sequence */
344         buf[0]='?';
345         txrx(lpc,buf,1,TXRX_TYPE_BAUD);
346         if(strncmp(buf,"Synchronized\r\n",14)) {
347                 printf("auto baud detection failed\n");
348                 return -1;
349         }
350
351         /* tell bl that we are synchronized (it's allready in buf) */
352         txrx(lpc,buf,14,TXRX_TYPE_SYNC);
353         if(strncmp(buf,"OK\r\n",4)) {
354                 printf("sync failed\n");
355                 return -1;
356         }
357
358         /* tell bl the crystal frequency */
359         len=strlen(lpc->freq)+2;
360         strncpy(buf,lpc->freq,BUFSIZE);
361         buf[len-2]='\r';
362         buf[len-1]='\n';
363         txrx(lpc,buf,len,TXRX_TYPE_SYNC);
364         if(strncmp(buf,"OK\r\n",4)) {
365                 printf("freq set failed\n");
366                 return -1;
367         }
368
369         return 0;
370 }
371
372 int unlock_go(t_lpc *lpc) {
373
374         char buf[BUFSIZE];
375         int ret;
376
377         memcpy(buf,"U 23130\r\n",9);
378         ret=txrx(lpc,buf,9,TXRX_TYPE_CMD);
379
380         return ret;
381 }
382
383 int go(t_lpc *lpc) {
384
385         char buf[BUFSIZE];
386         int ret,len;
387
388         snprintf(buf,BUFSIZE,"G %d A\r\n",lpc->jaddr);
389         len=strlen(buf);
390         ret=txrx(lpc,buf,len,TXRX_TYPE_GO);
391
392         return ret;
393 }
394
395 int uuencode(u8 *in,u8 *out,int len) {
396
397         out[0]=0x20+len;
398         out[1]=0x20+((in[0]>>2)&0x3f);
399         out[2]=0x20+(((in[0]<<4)|(in[1]>>4))&0x3f);
400         out[3]=0x20+(((in[1]<<2)|(in[2]>>6))&0x3f);
401         out[4]=0x20+(in[2]&0x3f);
402
403         return 0;
404 }
405
406 int write_to_ram(t_lpc *lpc,char *buf,u32 addr,int len) {
407
408         int lcount;
409         u32 checksum;
410         char txrxbuf[BUFSIZE];
411         int count,bcnt;
412         int nlen,slen;
413         int i;
414
415         /* check length */
416         if(len%4) {
417                 printf("ram write: not a multiple of 4\n");
418                 return -1;
419         }
420
421         /* make it a multiple of 3 (reason: uuencode) */
422         nlen=(!(len%3))?len:((len/3+1)*3);
423         if(nlen>BUFSIZE) {
424                 printf("ram write: too much data\n");
425                 return -1;
426         }
427         for(i=len;i<nlen;i++) buf[i]=0;
428
429         /* prepare addr */
430         addr+=lpc->roff;
431
432         /* prepare write command */
433         if(lpc->info&VERBOSE)
434                 printf("writing 0x%02x bytes to 0x%08x\n",len,addr);
435         snprintf(txrxbuf,BUFSIZE,"W %d %d\r\n",addr,len);
436         slen=strlen(txrxbuf);
437
438         /* send command and check return code */
439         txrx(lpc,txrxbuf,slen,TXRX_TYPE_CMD);
440
441         /* send data */
442         lcount=0;
443         bcnt=0;
444         count=0;
445         checksum=0;
446         while(bcnt<nlen) {
447
448                 /* uuencode / prepare data bytes */
449                 uuencode((u8 *)(buf+bcnt),(u8 *)(txrxbuf),
450                          (bcnt==nlen-3)?(len%3?len%3:3):3);
451                 txrxbuf[5]='\r';
452                 txrxbuf[6]='\n';
453
454                 /* checksum */
455                 checksum+=((u8)buf[bcnt]+(u8)buf[bcnt+1]+(u8)buf[bcnt+2]);
456
457                 /* send a data line */
458                 txrx(lpc,txrxbuf,7,TXRX_TYPE_DATA);
459
460                 /* increase counters */
461                 lcount+=1;
462                 bcnt+=3;
463                 count+=3;
464
465                 /* checksum */
466                 if((!(lcount%20))|(bcnt==nlen)) {
467                         /* send backtick */
468                         memcpy(txrxbuf,"`\r\n",3);
469                         //txrx(lpc,txrxbuf,3,TXRX_TYPE_DATA);
470                         /* send checksum */
471                         snprintf(txrxbuf,BUFSIZE,"%d\r\n",checksum);
472                         slen=strlen(txrxbuf);
473                         txrx(lpc,txrxbuf,slen,TXRX_TYPE_CKSM);
474                         if(!strncmp(txrxbuf,"RESE",4)) {
475                                 read(lpc->sfd,txrxbuf+4,4);
476                                 printf("ram write: resending ...\n");
477                                 bcnt-=count;
478                         }
479                         if(strncmp(txrxbuf,"OK\r\n",4)) {
480                                 printf("ram write: bad response\n");
481                                 return -1;
482                         }
483                         /* reset checksum & counter */
484                         checksum=0;
485                         count=0;
486                 }
487
488         }
489
490         return 0;
491 }
492
493 int firmware_to_ram(t_lpc *lpc) {
494
495         char buf[BUFSIZE];
496         u32 addr,len,type;
497         int ret,temp;
498
499         /* read a line */
500         ret=1;
501         while(ret) {
502                 /* sync line */
503                 ret=read(lpc->fwfd,buf,1);
504                 switch(buf[0]) {
505                         case '\r':
506                                 continue;
507                         case '\n':
508                                 continue;
509                         case ':':
510                                 /* start code */
511                                 break;
512                         default:
513                                 printf("fw to ram: no ihex format\n");
514                                 return -1;
515                 }
516                 /* read len */
517                 ret=read(lpc->fwfd,buf,2);
518                 sscanf(buf,"%02x",&len);
519                 /* read addr */
520                 ret=read(lpc->fwfd,buf,4);
521                 sscanf(buf,"%04x",&addr);
522                 /* read type */
523                 ret=read(lpc->fwfd,buf,2);
524                 sscanf(buf,"%02x",&type);
525                 /* successfull return if type is end of file */
526                 if(type==0x01)
527                         return 0;
528                 /* read data (and cksum) */
529                 ret=read(lpc->fwfd,buf,2*(len+1));
530                 if(ret!=(2*(len+1))) {
531                         printf("fw to ram: data missing\n");
532                                 return -1;
533                 }
534                 for(ret=0;ret<len;ret++) {
535                         sscanf(buf+2*ret,"%02x",&temp);
536                         buf[ret]=temp;
537                 }
538                 /* act according to type */
539                 switch(type) {
540                         //case 0x03:
541                         //      /* get cs and ip */
542                         //      break;
543                         case 0x00:
544                                 if(len%4) {
545                                         printf("fw to ram: invalid len\n");
546                                         return -1;
547                                 }
548                                 write_to_ram(lpc,buf,addr,len);
549                                 break;
550                         case 0x04:
551                                 lpc->roff=((buf[0]<<24)|(buf[1]<<16));
552                                 break;
553                         case 0x05:
554                                 lpc->jaddr=((buf[0]<<24)|(buf[1]<<16));
555                                 lpc->jaddr|=((buf[2]<<8)|buf[3]);
556                                 break;
557                         default:
558                                 printf("fw to ram: unknown type %02x\n",type);
559                                 return -1;
560                 }
561         }
562
563         return 0;
564 }
565
566 int lpc_txbuf_flush(t_lpc *lpc) {
567
568         int i,ret;
569         u8 buf[16];
570
571         ret=1;
572         printf("flushing lpc tx buffer: ");
573         while(ret) {
574                 ret=read(lpc->sfd,buf,16);
575                 for(i=0;i<ret;i++)
576                         printf("%02x ",buf[i]);
577         }
578         printf("\n");
579
580         return 0;
581 }
582
583 int dump_files(int sfd,int dfd,u32 addr,u32 len) {
584
585         int ret;
586         int size;
587         int cnt;
588         int i;
589         u8 buf[16];
590
591         printf("dumping content (addr=0x%08x, len=0x%08x) ...\n",addr,len);
592
593         /* send cmd */
594         size=1+4+4;
595         cnt=0;
596         buf[0]=CMD_READ;
597         buf[1]=(addr>>24)&0xff;
598         buf[2]=(addr>>16)&0xff;
599         buf[3]=(addr>>8)&0xff;
600         buf[4]=addr&0xff;
601         buf[5]=(len>>24)&0xff;
602         buf[6]=(len>>16)&0xff;
603         buf[7]=(len>>8)&0xff;
604         buf[8]=len&0xff;
605         printf("  sending cmd: ");
606         while(size) {
607                 ret=write(sfd,buf+cnt,size);
608                 for(i=cnt;i<cnt+ret;i++)
609                         printf("%02x ",buf[i]);
610                 if(ret<0) {
611                         perror("dump file: send cmd ");
612                         return ret;
613                 }
614                 size-=ret;
615                 cnt+=ret;
616         }
617         printf("\n");
618
619         /* receive data and dump it to file */
620         ret=1;
621         cnt=0;
622         printf("  receiving data ...\n");
623         while(ret) {
624                 ret=read(sfd,buf,16);
625                 if(ret<0) {
626                         perror("dump file: read data");
627                         return ret;
628                 }
629                 size=ret;
630                 cnt=0;
631                 while(size) {
632                         ret=write(dfd,buf+cnt,size-cnt);
633                         if(ret<0) {
634                                 perror("dump file: write data");
635                                 return ret;
636                         }
637                         cnt+=ret;
638                         size-=ret;
639                 }
640         }
641
642         return 0;
643 }
644
645 int main(int argc,char **argv) {
646
647         t_lpc lpc;
648         int i;
649         int ret;
650
651         /*
652          * initial ... 
653          */
654
655         memset(&lpc,0,sizeof(t_lpc));
656         strncpy(lpc.freq,CRYSTFREQ,7);
657         lpc.roff=RAMOFFSET;
658         lpc.jaddr=RAMOFFSET;
659
660         /* parse argv */
661
662         for(i=1;i<argc;i++) {
663
664                 if(argv[i][0]!='-') {
665                         usage();
666                         return -1;
667                 }
668
669                 switch(argv[i][1]) {
670                         case 'd':
671                                 strncpy(lpc.sdev,argv[++i],127);
672                                 break;
673                         case 'f':
674                                 strncpy(lpc.fwfile,argv[++i],127);
675                                 lpc.info|=FIRMWARE;
676                                 break;
677                         case 'v':
678                                 lpc.info|=VERBOSE;
679                                 break;
680                         case 'c':
681                                 strncpy(lpc.freq,argv[++i],7);
682                                 break;
683                         case 'D':
684                                 if(argv[i][2]=='0') {
685                                         lpc.info|=BANK0;
686                                         strncpy(lpc.bank0,argv[++i],127);
687                                         break;
688                                 }
689                                 else if(argv[i][2]=='2') {
690                                         lpc.info|=BANK2;
691                                         strncpy(lpc.bank2,argv[++i],127);
692                                         break;
693                                 }
694                                 else if(argv[i][2]=='b') {
695                                         lpc.info|=BL;
696                                         strncpy(lpc.bl,argv[++i],127);
697                                         break;
698                                 }
699                                 else {
700                                         usage();
701                                         return -1;
702                                 }
703                                 
704                         default:
705                                 usage();
706                                 return -1;
707                 }
708
709         }
710
711         /* open serial port */
712         if(open_serial_device(&lpc)<0)
713                 goto end;
714
715         /* boot loader init */
716         printf("boot loader init ...\n");
717         if(bl_init(&lpc)<0)
718                 return -1;
719
720         /* quit if there is no hex file to process */
721         if(!(lpc.info&FIRMWARE)) {
722                 printf("no firmware -> aborting\n");
723                 goto end;
724         }
725
726         /* open firmware file */
727         if(open_firmware(&lpc)<0)
728                 goto end;
729
730         /* open dump files */
731         if(open_dumpfiles(&lpc)<0)
732                 goto end;
733
734         /* parse intel hex file and write to ram */
735         printf("write firmware to ram ...\n");
736         firmware_to_ram(&lpc);
737
738         /* unlock go cmd */
739         printf("unlock go command ...\n");
740         unlock_go(&lpc);
741
742         /* go! */
743         printf("go ...\n");
744         ret=go(&lpc);
745
746         /* flush the lpc2220 tx buf */
747         lpc_txbuf_flush(&lpc);
748
749         /* reconfigure the serial port */
750         if(reconfig_serial_device(&lpc)<0)
751                 goto end;
752
753         /* download flash/bootloader content */
754         if(lpc.info&BANK0)
755                 dump_files(lpc.sfd,lpc.b0fd,BANK0_ADDR,BANK_SIZE);
756         if(lpc.info&BANK2)
757                 dump_files(lpc.sfd,lpc.b2fd,BANK2_ADDR,BANK_SIZE);
758         if(lpc.info&BL)
759                 dump_files(lpc.sfd,lpc.blfd,BL_ADDR,BL_SIZE);
760
761 end:
762         if(lpc.sfd)
763                 close(lpc.sfd);
764         if(lpc.fwfd)
765                 close(lpc.fwfd);
766         if(lpc.b0fd)
767                 close(lpc.b0fd);
768         if(lpc.b2fd)
769                 close(lpc.b2fd);
770         if(lpc.blfd)
771                 close(lpc.blfd);
772
773         return 0;
774 }
775