2 * Boot a Marvell SoC, with Xmodem over UART0.
3 * supports Kirkwood, Dove, Armada 370, Armada XP, Armada 375, Armada 38x and
6 * (c) 2012 Daniel Stodden <daniel.stodden@gmail.com>
7 * (c) 2021 Pali Rohár <pali@kernel.org>
8 * (c) 2021 Marek Behún <marek.behun@nic.cz>
10 * References: marvell.com, "88F6180, 88F6190, 88F6192, and 88F6281
11 * Integrated Controller: Functional Specifications" December 2,
12 * 2008. Chapter 24.2 "BootROM Firmware".
33 #include "termios_linux.h"
39 * Marvell BootROM UART Sensing
42 static unsigned char kwboot_msg_boot[] = {
43 0xBB, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
46 static unsigned char kwboot_msg_debug[] = {
47 0xDD, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
50 /* Defines known to work on Kirkwood */
51 #define KWBOOT_MSG_REQ_DELAY 10 /* ms */
52 #define KWBOOT_MSG_RSP_TIMEO 50 /* ms */
54 /* Defines known to work on Armada XP */
55 #define KWBOOT_MSG_REQ_DELAY_AXP 1000 /* ms */
56 #define KWBOOT_MSG_RSP_TIMEO_AXP 1000 /* ms */
62 #define SOH 1 /* sender start of block header */
63 #define EOT 4 /* sender end of block transfer */
64 #define ACK 6 /* target block ack */
65 #define NAK 21 /* target block negative ack */
67 #define KWBOOT_XM_BLKSZ 128 /* xmodem block size */
73 uint8_t data[KWBOOT_XM_BLKSZ];
77 #define KWBOOT_BLK_RSP_TIMEO 2000 /* ms */
78 #define KWBOOT_HDR_RSP_TIMEO 10000 /* ms */
80 /* ARM code to change baudrate */
81 static unsigned char kwboot_baud_code[] = {
82 /* ; #define UART_BASE 0xd0012000 */
83 /* ; #define DLL 0x00 */
84 /* ; #define DLH 0x04 */
85 /* ; #define LCR 0x0c */
86 /* ; #define DLAB 0x80 */
87 /* ; #define LSR 0x14 */
88 /* ; #define TEMT 0x40 */
89 /* ; #define DIV_ROUND(a, b) ((a + b/2) / b) */
91 /* ; u32 set_baudrate(u32 old_b, u32 new_b) { */
93 /* ; (!(readl(UART_BASE + LSR) & TEMT)); */
94 /* ; u32 lcr = readl(UART_BASE + LCR); */
95 /* ; writel(UART_BASE + LCR, lcr | DLAB); */
96 /* ; u8 old_dll = readl(UART_BASE + DLL); */
97 /* ; u8 old_dlh = readl(UART_BASE + DLH); */
98 /* ; u16 old_dl = old_dll | (old_dlh << 8); */
99 /* ; u32 clk = old_b * old_dl; */
100 /* ; u16 new_dl = DIV_ROUND(clk, new_b); */
101 /* ; u8 new_dll = new_dl & 0xff; */
102 /* ; u8 new_dlh = (new_dl >> 8) & 0xff; */
103 /* ; writel(UART_BASE + DLL, new_dll); */
104 /* ; writel(UART_BASE + DLH, new_dlh); */
105 /* ; writel(UART_BASE + LCR, lcr & ~DLAB); */
110 /* ; r0 = UART_BASE */
111 0x0d, 0x02, 0xa0, 0xe3, /* mov r0, #0xd0000000 */
112 0x12, 0x0a, 0x80, 0xe3, /* orr r0, r0, #0x12000 */
114 /* ; Wait until Transmitter FIFO is Empty */
115 /* .Lloop_txempty: */
116 /* ; r1 = UART_BASE[LSR] & TEMT */
117 0x14, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x14] */
118 0x40, 0x00, 0x11, 0xe3, /* tst r1, #0x40 */
119 0xfc, 0xff, 0xff, 0x0a, /* beq .Lloop_txempty */
121 /* ; Set Divisor Latch Access Bit */
122 /* ; UART_BASE[LCR] |= DLAB */
123 0x0c, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x0c] */
124 0x80, 0x10, 0x81, 0xe3, /* orr r1, r1, #0x80 */
125 0x0c, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0c] */
127 /* ; Read current Divisor Latch */
128 /* ; r1 = UART_BASE[DLH]<<8 | UART_BASE[DLL] */
129 0x00, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x00] */
130 0xff, 0x10, 0x01, 0xe2, /* and r1, r1, #0xff */
131 0x01, 0x20, 0xa0, 0xe1, /* mov r2, r1 */
132 0x04, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x04] */
133 0xff, 0x10, 0x01, 0xe2, /* and r1, r1, #0xff */
134 0x41, 0x14, 0xa0, 0xe1, /* asr r1, r1, #8 */
135 0x02, 0x10, 0x81, 0xe1, /* orr r1, r1, r2 */
137 /* ; Read old baudrate value */
138 /* ; r2 = old_baudrate */
139 0x74, 0x20, 0x9f, 0xe5, /* ldr r2, old_baudrate */
141 /* ; Calculate base clock */
143 0x92, 0x01, 0x01, 0xe0, /* mul r1, r2, r1 */
145 /* ; Read new baudrate value */
146 /* ; r2 = new_baudrate */
147 0x70, 0x20, 0x9f, 0xe5, /* ldr r2, new_baudrate */
149 /* ; Calculate new Divisor Latch */
150 /* ; r1 = DIV_ROUND(r1, r2) = */
151 /* ; = (r1 + r2/2) / r2 */
152 0xa2, 0x10, 0x81, 0xe0, /* add r1, r1, r2, lsr #1 */
153 0x02, 0x40, 0xa0, 0xe1, /* mov r4, r2 */
154 0xa1, 0x00, 0x54, 0xe1, /* cmp r4, r1, lsr #1 */
156 0x84, 0x40, 0xa0, 0x91, /* movls r4, r4, lsl #1 */
157 0xa1, 0x00, 0x54, 0xe1, /* cmp r4, r1, lsr #1 */
158 0xfc, 0xff, 0xff, 0x9a, /* bls .Lloop_div1 */
159 0x00, 0x30, 0xa0, 0xe3, /* mov r3, #0 */
161 0x04, 0x00, 0x51, 0xe1, /* cmp r1, r4 */
162 0x04, 0x10, 0x41, 0x20, /* subhs r1, r1, r4 */
163 0x03, 0x30, 0xa3, 0xe0, /* adc r3, r3, r3 */
164 0xa4, 0x40, 0xa0, 0xe1, /* mov r4, r4, lsr #1 */
165 0x02, 0x00, 0x54, 0xe1, /* cmp r4, r2 */
166 0xf9, 0xff, 0xff, 0x2a, /* bhs .Lloop_div2 */
167 0x03, 0x10, 0xa0, 0xe1, /* mov r1, r3 */
169 /* ; Set new Divisor Latch Low */
170 /* ; UART_BASE[DLL] = r1 & 0xff */
171 0x01, 0x20, 0xa0, 0xe1, /* mov r2, r1 */
172 0xff, 0x20, 0x02, 0xe2, /* and r2, r2, #0xff */
173 0x00, 0x20, 0x80, 0xe5, /* str r2, [r0, #0x00] */
175 /* ; Set new Divisor Latch High */
176 /* ; UART_BASE[DLH] = r1>>8 & 0xff */
177 0x41, 0x24, 0xa0, 0xe1, /* asr r2, r1, #8 */
178 0xff, 0x20, 0x02, 0xe2, /* and r2, r2, #0xff */
179 0x04, 0x20, 0x80, 0xe5, /* str r2, [r0, #0x04] */
181 /* ; Clear Divisor Latch Access Bit */
182 /* ; UART_BASE[LCR] &= ~DLAB */
183 0x0c, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x0c] */
184 0x80, 0x10, 0xc1, 0xe3, /* bic r1, r1, #0x80 */
185 0x0c, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0c] */
187 /* ; Loop 0x2dc000 (2998272) cycles */
188 /* ; which is about 5ms on 1200 MHz CPU */
189 /* ; r1 = 0x2dc000 */
190 0xb7, 0x19, 0xa0, 0xe3, /* mov r1, #0x2dc000 */
192 0x01, 0x10, 0x41, 0xe2, /* sub r1, r1, #1 */
193 0x00, 0x00, 0x51, 0xe3, /* cmp r1, #0 */
194 0xfc, 0xff, 0xff, 0x1a, /* bne .Lloop_sleep */
196 /* ; Jump to the end of execution */
197 0x01, 0x00, 0x00, 0xea, /* b end */
199 /* ; Placeholder for old baudrate value */
201 0x00, 0x00, 0x00, 0x00, /* .word 0 */
203 /* ; Placeholder for new baudrate value */
205 0x00, 0x00, 0x00, 0x00, /* .word 0 */
210 /* ARM code from binary header executed by BootROM before changing baudrate */
211 static unsigned char kwboot_baud_code_binhdr_pre[] = {
212 /* ; #define UART_BASE 0xd0012000 */
213 /* ; #define THR 0x00 */
214 /* ; #define LSR 0x14 */
215 /* ; #define THRE 0x20 */
217 /* ; void send_preamble(void) { */
218 /* ; const u8 *str = "$baudratechange"; */
222 /* ; ((readl(UART_BASE + LSR) & THRE)); */
224 /* ; writel(UART_BASE + THR, c); */
228 /* ; Preserve registers for BootROM */
229 0xfe, 0x5f, 0x2d, 0xe9, /* push { r1 - r12, lr } */
231 /* ; r0 = UART_BASE */
232 0x0d, 0x02, 0xa0, 0xe3, /* mov r0, #0xd0000000 */
233 0x12, 0x0a, 0x80, 0xe3, /* orr r0, r0, #0x12000 */
235 /* ; r2 = address of preamble string */
236 0x00, 0x20, 0x8f, 0xe2, /* adr r2, .Lstr_preamble */
238 /* ; Skip preamble data section */
239 0x03, 0x00, 0x00, 0xea, /* b .Lloop_preamble */
241 /* ; Preamble string */
242 /* .Lstr_preamble: */
243 0x24, 0x62, 0x61, 0x75, /* .asciz "$baudratechange" */
244 0x64, 0x72, 0x61, 0x74,
245 0x65, 0x63, 0x68, 0x61,
246 0x6e, 0x67, 0x65, 0x00,
248 /* ; Send preamble string over UART */
249 /* .Lloop_preamble: */
251 /* ; Wait until Transmitter Holding is Empty */
253 /* ; r1 = UART_BASE[LSR] & THRE */
254 0x14, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x14] */
255 0x20, 0x00, 0x11, 0xe3, /* tst r1, #0x20 */
256 0xfc, 0xff, 0xff, 0x0a, /* beq .Lloop_thre */
258 /* ; Put character into Transmitter FIFO */
260 0x01, 0x10, 0xd2, 0xe4, /* ldrb r1, [r2], #1 */
261 /* ; UART_BASE[THR] = r1 */
262 0x00, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0] */
264 /* ; Loop until end of preamble string */
265 0x00, 0x00, 0x51, 0xe3, /* cmp r1, #0 */
266 0xf8, 0xff, 0xff, 0x1a, /* bne .Lloop_preamble */
269 /* ARM code for returning from binary header back to BootROM */
270 static unsigned char kwboot_baud_code_binhdr_post[] = {
271 /* ; Return 0 - no error */
272 0x00, 0x00, 0xa0, 0xe3, /* mov r0, #0 */
273 0xfe, 0x9f, 0xbd, 0xe8, /* pop { r1 - r12, pc } */
276 /* ARM code for jumping to the original image exec_addr */
277 static unsigned char kwboot_baud_code_data_jump[] = {
278 0x04, 0xf0, 0x1f, 0xe5, /* ldr pc, exec_addr */
279 /* ; Placeholder for exec_addr */
281 0x00, 0x00, 0x00, 0x00, /* .word 0 */
284 static const char kwb_baud_magic[16] = "$baudratechange";
286 static int kwboot_verbose;
288 static int msg_req_delay = KWBOOT_MSG_REQ_DELAY;
289 static int msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO;
290 static int blk_rsp_timeo = KWBOOT_BLK_RSP_TIMEO;
293 kwboot_write(int fd, const char *buf, size_t len)
298 ssize_t wr = write(fd, buf + tot, len - tot);
300 if (wr < 0 && errno == EINTR)
312 kwboot_printv(const char *fmt, ...)
316 if (kwboot_verbose) {
327 const char seq[] = { '-', '\\', '|', '/' };
329 static int state, bs;
331 if (state % div == 0) {
333 fputc(seq[state / div % sizeof(seq)], stdout);
349 __progress(int pct, char c)
351 const int width = 70;
352 static const char *nl = "";
355 if (pos % width == 0)
356 printf("%s%3d %% [", nl, pct);
361 pos = (pos + 1) % width;
364 while (pos && pos++ < width)
376 kwboot_progress(int _pct, char c)
391 kwboot_tty_recv(int fd, void *buf, size_t len, int timeo)
404 tv.tv_usec = timeo * 1000;
405 if (tv.tv_usec > 1000000) {
406 tv.tv_sec += tv.tv_usec / 1000000;
407 tv.tv_usec %= 1000000;
411 nfds = select(fd + 1, &rfds, NULL, NULL, &tv);
412 if (nfds < 0 && errno == EINTR)
421 n = read(fd, buf, len);
422 if (n < 0 && errno == EINTR)
427 buf = (char *)buf + n;
437 kwboot_tty_send(int fd, const void *buf, size_t len, int nodrain)
442 if (kwboot_write(fd, buf, len) < 0)
452 kwboot_tty_send_char(int fd, unsigned char c)
454 return kwboot_tty_send(fd, &c, 1, 0);
458 kwboot_tty_baudrate_to_speed(int baudrate)
607 _is_within_tolerance(int value, int reference, int tolerance)
609 return 100 * value >= reference * (100 - tolerance) &&
610 100 * value <= reference * (100 + tolerance);
614 kwboot_tty_change_baudrate(int fd, int baudrate)
620 rc = tcgetattr(fd, &tio);
624 speed = kwboot_tty_baudrate_to_speed(baudrate);
632 tio.c_ospeed = tio.c_ispeed = baudrate;
635 rc = cfsetospeed(&tio, speed);
639 rc = cfsetispeed(&tio, speed);
643 rc = tcsetattr(fd, TCSANOW, &tio);
647 rc = tcgetattr(fd, &tio);
651 if (cfgetospeed(&tio) != speed || cfgetispeed(&tio) != speed)
656 * Check whether set baudrate is within 3% tolerance.
657 * If BOTHER is defined, Linux always fills out c_ospeed / c_ispeed
660 if (!_is_within_tolerance(tio.c_ospeed, baudrate, 3))
663 if (!_is_within_tolerance(tio.c_ispeed, baudrate, 3))
670 fprintf(stderr, "Could not set baudrate to requested value\n");
676 kwboot_open_tty(const char *path, int baudrate)
683 fd = open(path, O_RDWR | O_NOCTTY | O_NDELAY);
687 rc = tcgetattr(fd, &tio);
692 tio.c_cflag |= CREAD | CLOCAL;
693 tio.c_cflag &= ~(CSTOPB | HUPCL | CRTSCTS);
697 rc = tcsetattr(fd, TCSANOW, &tio);
701 flags = fcntl(fd, F_GETFL);
705 rc = fcntl(fd, F_SETFL, flags & ~O_NDELAY);
709 rc = kwboot_tty_change_baudrate(fd, baudrate);
724 kwboot_bootmsg(int tty, void *msg)
726 struct kwboot_block block;
732 kwboot_printv("Please reboot the target into UART boot mode...");
734 kwboot_printv("Sending boot message. Please reboot the target...");
737 rc = tcflush(tty, TCIOFLUSH);
741 for (count = 0; count < 128; count++) {
742 rc = kwboot_tty_send(tty, msg, 8, 0);
744 usleep(msg_req_delay * 1000);
749 rc = kwboot_tty_recv(tty, &c, 1, msg_rsp_timeo);
753 } while (rc || c != NAK);
761 * At this stage we have sent more boot message patterns and BootROM
762 * (at least on Armada XP and 385) started interpreting sent bytes as
763 * part of xmodem packets. If BootROM is expecting SOH byte as start of
764 * a xmodem packet and it receives byte 0xff, then it throws it away and
765 * sends a NAK reply to host. If BootROM does not receive any byte for
766 * 2s when expecting some continuation of the xmodem packet, it throws
767 * away the partially received xmodem data and sends NAK reply to host.
769 * Therefore for starting xmodem transfer we have two options: Either
770 * wait 2s or send 132 0xff bytes (which is the size of xmodem packet)
771 * to ensure that BootROM throws away any partially received data.
774 /* flush output queue with remaining boot message patterns */
775 tcflush(tty, TCOFLUSH);
777 /* send one xmodem packet with 0xff bytes to force BootROM to re-sync */
778 memset(&block, 0xff, sizeof(block));
779 kwboot_tty_send(tty, &block, sizeof(block), 0);
782 * Sending 132 bytes via 115200B/8-N-1 takes 11.45 ms, reading 132 bytes
783 * takes 11.45 ms, so waiting for 30 ms should be enough.
787 /* flush remaining NAK replies from input queue */
788 tcflush(tty, TCIFLUSH);
794 kwboot_debugmsg(int tty, void *msg)
798 kwboot_printv("Sending debug message. Please reboot the target...");
803 rc = tcflush(tty, TCIOFLUSH);
807 rc = kwboot_tty_send(tty, msg, 8, 0);
809 usleep(msg_req_delay * 1000);
813 rc = kwboot_tty_recv(tty, buf, 16, msg_rsp_timeo);
825 kwboot_xm_makeblock(struct kwboot_block *block, const void *data,
826 size_t size, int pnum)
832 block->_pnum = ~block->pnum;
834 n = size < KWBOOT_XM_BLKSZ ? size : KWBOOT_XM_BLKSZ;
835 memcpy(&block->data[0], data, n);
836 memset(&block->data[n], 0, KWBOOT_XM_BLKSZ - n);
839 for (i = 0; i < n; i++)
840 block->csum += block->data[i];
850 if (clock_gettime(CLOCK_MONOTONIC, &ts)) {
851 static int err_print;
854 perror("clock_gettime() does not work");
858 /* this will just make the timeout not work */
862 return ts.tv_sec * 1000ULL + (ts.tv_nsec + 500000) / 1000000;
868 return c == ACK || c == NAK;
872 _xm_reply_to_error(int c)
892 kwboot_baud_magic_handle(int fd, char c, int baudrate)
894 static size_t rcv_len;
896 if (rcv_len < sizeof(kwb_baud_magic)) {
897 /* try to recognize whole magic word */
898 if (c == kwb_baud_magic[rcv_len]) {
901 printf("%.*s%c", (int)rcv_len, kwb_baud_magic, c);
907 if (rcv_len == sizeof(kwb_baud_magic)) {
908 /* magic word received */
909 kwboot_printv("\nChanging baudrate to %d Bd\n", baudrate);
911 return kwboot_tty_change_baudrate(fd, baudrate) ? : 1;
918 kwboot_xm_recv_reply(int fd, char *c, int stop_on_non_xm,
919 int ignore_nak_reply,
920 int allow_non_xm, int *non_xm_print,
921 int baudrate, int *baud_changed)
923 int timeout = allow_non_xm ? KWBOOT_HDR_RSP_TIMEO : blk_rsp_timeo;
924 uint64_t recv_until = _now() + timeout;
928 rc = kwboot_tty_recv(fd, c, 1, timeout);
930 if (errno != ETIMEDOUT)
932 else if (allow_non_xm && *non_xm_print)
938 /* If received xmodem reply, end. */
939 if (_is_xm_reply(*c)) {
940 if (*c == NAK && ignore_nak_reply) {
941 timeout = recv_until - _now();
949 * If receiving/printing non-xmodem text output is allowed and
950 * such a byte was received, we want to increase receiving time
952 * - print the byte, if it is not part of baudrate change magic
953 * sequence while baudrate change was requested (-B option)
955 * Otherwise decrease timeout by time elapsed.
958 recv_until = _now() + timeout;
960 if (baudrate && !*baud_changed) {
961 rc = kwboot_baud_magic_handle(fd, *c, baudrate);
968 } else if (!baudrate || !*baud_changed) {
976 timeout = recv_until - _now();
988 kwboot_xm_sendblock(int fd, struct kwboot_block *block, int allow_non_xm,
989 int *done_print, int baudrate, int allow_retries)
991 int non_xm_print, baud_changed;
992 int rc, err, retries;
1001 rc = kwboot_tty_send(fd, block, sizeof(*block), 1);
1005 if (allow_non_xm && !*done_print) {
1006 kwboot_progress(100, '.');
1007 kwboot_printv("Done\n");
1011 rc = kwboot_xm_recv_reply(fd, &c, retries < 3,
1013 allow_non_xm, &non_xm_print,
1014 baudrate, &baud_changed);
1018 if (!allow_non_xm && c != ACK) {
1019 if (c == NAK && allow_retries && retries + 1 < 16)
1020 kwboot_progress(-1, '+');
1022 kwboot_progress(-1, 'E');
1024 } while (c == NAK && allow_retries && retries++ < 16);
1027 kwboot_printv("\n");
1029 if (allow_non_xm && baudrate && !baud_changed) {
1030 fprintf(stderr, "Baudrate was not changed\n");
1035 return _xm_reply_to_error(c);
1038 kwboot_printv("\n");
1044 kwboot_xm_finish(int fd)
1049 kwboot_printv("Finishing transfer\n");
1053 rc = kwboot_tty_send_char(fd, EOT);
1057 rc = kwboot_xm_recv_reply(fd, &c, retries < 3,
1062 } while (c == NAK && retries++ < 16);
1064 return _xm_reply_to_error(c);
1068 kwboot_xmodem_one(int tty, int *pnum, int header, const uint8_t *data,
1069 size_t size, int baudrate)
1075 kwboot_printv("Sending boot image %s (%zu bytes)...\n",
1076 header ? "header" : "data", size);
1081 while (sent < size) {
1082 struct kwboot_block block;
1086 blksz = kwboot_xm_makeblock(&block, data, left, (*pnum)++);
1089 last_block = (left <= blksz);
1092 * Handling of repeated xmodem packets is completely broken in
1093 * Armada 385 BootROM - it completely ignores xmodem packet
1094 * numbers, they are only used for checksum verification.
1095 * BootROM can handle a retry of the xmodem packet only during
1096 * the transmission of kwbimage header and only if BootROM
1097 * itself sent NAK response to previous attempt (it does it on
1098 * checksum failure). During the transmission of kwbimage data
1099 * part, BootROM always expects next xmodem packet, even if it
1100 * sent NAK to previous attempt - there is absolutely no way to
1101 * repair incorrectly transmitted xmodem packet during kwbimage
1102 * data part upload. Also, if kwboot receives non-ACK/NAK
1103 * response (meaning that original BootROM response was damaged
1104 * on UART) there is no way to detect if BootROM accepted xmodem
1105 * packet or not and no way to check if kwboot could repeat the
1108 * Stop transfer and return failure if kwboot receives unknown
1109 * reply if non-xmodem reply is not allowed (for all xmodem
1110 * packets except the last header packet) or when non-ACK reply
1111 * is received during data part transfer.
1113 rc = kwboot_xm_sendblock(tty, &block, header && last_block,
1114 &done_print, baudrate, header);
1122 kwboot_progress(sent * 100 / size, '.');
1126 kwboot_printv("Done\n");
1130 kwboot_printv("\n");
1135 kwboot_xmodem(int tty, const void *_img, size_t size, int baudrate)
1137 const uint8_t *img = _img;
1141 hdrsz = kwbheader_size(img);
1144 * If header size is not aligned to xmodem block size (which applies
1145 * for all images in kwbimage v0 format) then we have to ensure that
1146 * the last xmodem block of header contains beginning of the data
1147 * followed by the header. So align header size to xmodem block size.
1149 hdrsz += (KWBOOT_XM_BLKSZ - hdrsz % KWBOOT_XM_BLKSZ) % KWBOOT_XM_BLKSZ;
1153 rc = kwboot_xmodem_one(tty, &pnum, 1, img, hdrsz, baudrate);
1158 * If we have already sent image data as a part of the last
1159 * xmodem header block then we have nothing more to send.
1164 rc = kwboot_xmodem_one(tty, &pnum, 0, img, size, 0);
1169 rc = kwboot_xm_finish(tty);
1174 kwboot_printv("\nChanging baudrate back to 115200 Bd\n\n");
1175 rc = kwboot_tty_change_baudrate(tty, 115200);
1184 kwboot_term_pipe(int in, int out, const char *quit, int *s)
1189 nin = read(in, buf, sizeof(buf));
1196 for (i = 0; i < nin; i++) {
1197 if (buf[i] == quit[*s]) {
1204 if (*s > i && kwboot_write(out, quit, *s - i) < 0)
1214 if (kwboot_write(out, buf, nin) < 0)
1221 kwboot_terminal(int tty)
1224 const char *quit = "\34c";
1225 struct termios otio, tio;
1231 rc = tcgetattr(in, &otio);
1235 rc = tcsetattr(in, TCSANOW, &tio);
1238 perror("tcsetattr");
1242 kwboot_printv("[Type Ctrl-%c + %c to quit]\r\n",
1243 quit[0] | 0100, quit[1]);
1256 nfds = nfds < tty ? tty : nfds;
1260 nfds = nfds < in ? in : nfds;
1263 nfds = select(nfds + 1, &rfds, NULL, NULL, NULL);
1267 if (FD_ISSET(tty, &rfds)) {
1268 rc = kwboot_term_pipe(tty, STDOUT_FILENO, NULL, NULL);
1273 if (in >= 0 && FD_ISSET(in, &rfds)) {
1274 rc = kwboot_term_pipe(in, tty, quit, &s);
1278 } while (quit[s] != 0);
1281 tcsetattr(in, TCSANOW, &otio);
1288 kwboot_read_image(const char *path, size_t *size, size_t reserve)
1298 fd = open(path, O_RDONLY);
1302 rc = fstat(fd, &st);
1306 img = malloc(st.st_size + reserve);
1311 while (tot < st.st_size) {
1312 ssize_t rd = read(fd, img + tot, st.st_size - tot);
1319 if (!rd && tot < st.st_size) {
1339 kwboot_hdr_csum8(const void *hdr)
1341 const uint8_t *data = hdr;
1345 size = kwbheader_size_for_csum(hdr);
1347 for (csum = 0; size-- > 0; data++)
1354 kwboot_img_csum32_ptr(void *img)
1356 struct main_hdr_v1 *hdr = img;
1359 datasz = le32_to_cpu(hdr->blocksize) - sizeof(uint32_t);
1361 return img + le32_to_cpu(hdr->srcaddr) + datasz;
1365 kwboot_img_csum32(const void *img)
1367 const struct main_hdr_v1 *hdr = img;
1368 uint32_t datasz, csum = 0;
1369 const uint32_t *data;
1371 datasz = le32_to_cpu(hdr->blocksize) - sizeof(csum);
1372 if (datasz % sizeof(uint32_t))
1375 data = img + le32_to_cpu(hdr->srcaddr);
1376 while (datasz > 0) {
1377 csum += le32_to_cpu(*data++);
1381 return cpu_to_le32(csum);
1385 kwboot_img_is_secure(void *img)
1387 struct opt_hdr_v1 *ohdr;
1389 for_each_opt_hdr_v1 (ohdr, img)
1390 if (ohdr->headertype == OPT_HDR_V1_SECURE_TYPE)
1397 kwboot_img_grow_data_right(void *img, size_t *size, size_t grow)
1399 struct main_hdr_v1 *hdr = img;
1403 * 32-bit checksum comes after end of image code, so we will be putting
1404 * new code there. So we get this pointer and then increase data size
1405 * (since increasing data size changes kwboot_img_csum32_ptr() return
1408 result = kwboot_img_csum32_ptr(img);
1409 hdr->blocksize = cpu_to_le32(le32_to_cpu(hdr->blocksize) + grow);
1416 kwboot_img_grow_hdr(void *img, size_t *size, size_t grow)
1418 uint32_t hdrsz, datasz, srcaddr;
1419 struct main_hdr_v1 *hdr = img;
1420 struct opt_hdr_v1 *ohdr;
1423 srcaddr = le32_to_cpu(hdr->srcaddr);
1425 /* calculate real used space in kwbimage header */
1426 if (kwbimage_version(img) == 0) {
1427 hdrsz = kwbheader_size(img);
1429 hdrsz = sizeof(*hdr);
1430 for_each_opt_hdr_v1 (ohdr, hdr)
1431 hdrsz += opt_hdr_v1_size(ohdr);
1434 data = (uint8_t *)img + srcaddr;
1435 datasz = *size - srcaddr;
1437 /* only move data if there is not enough space */
1438 if (hdrsz + grow > srcaddr) {
1439 size_t need = hdrsz + grow - srcaddr;
1441 /* move data by enough bytes */
1442 memmove(data + need, data, datasz);
1444 hdr->srcaddr = cpu_to_le32(srcaddr + need);
1448 if (kwbimage_version(img) == 1) {
1450 if (hdrsz > kwbheader_size(img)) {
1451 hdr->headersz_msb = hdrsz >> 16;
1452 hdr->headersz_lsb = cpu_to_le16(hdrsz & 0xffff);
1458 kwboot_add_bin_ohdr_v1(void *img, size_t *size, uint32_t binsz)
1460 struct main_hdr_v1 *hdr = img;
1461 struct opt_hdr_v1 *ohdr;
1468 for_each_opt_hdr_v1 (ohdr, img)
1469 if (opt_hdr_v1_next(ohdr) == NULL)
1472 prev_ext = opt_hdr_v1_ext(ohdr);
1473 ohdr = _opt_hdr_v1_next(ohdr);
1475 ohdr = (void *)(hdr + 1);
1476 prev_ext = &hdr->ext;
1480 * ARM executable code inside the BIN header on some mvebu platforms
1481 * (e.g. A370, AXP) must always be aligned with the 128-bit boundary.
1482 * This requirement can be met by inserting dummy arguments into
1483 * BIN header, if needed.
1485 offset = &ohdr->data[4] - (char *)img;
1486 num_args = ((16 - offset % 16) % 16) / sizeof(uint32_t);
1488 ohdrsz = sizeof(*ohdr) + 4 + 4 * num_args + binsz + 4;
1489 kwboot_img_grow_hdr(hdr, size, ohdrsz);
1493 ohdr->headertype = OPT_HDR_V1_BINARY_TYPE;
1494 ohdr->headersz_msb = ohdrsz >> 16;
1495 ohdr->headersz_lsb = cpu_to_le16(ohdrsz & 0xffff);
1497 memset(&ohdr->data[0], 0, ohdrsz - sizeof(*ohdr));
1498 *(uint32_t *)&ohdr->data[0] = cpu_to_le32(num_args);
1500 return &ohdr->data[4 + 4 * num_args];
1504 _inject_baudrate_change_code(void *img, size_t *size, int for_data,
1505 int old_baud, int new_baud)
1507 struct main_hdr_v1 *hdr = img;
1508 uint32_t orig_datasz;
1513 orig_datasz = le32_to_cpu(hdr->blocksize) - sizeof(uint32_t);
1515 codesz = sizeof(kwboot_baud_code) +
1516 sizeof(kwboot_baud_code_data_jump);
1517 code = kwboot_img_grow_data_right(img, size, codesz);
1519 codesz = sizeof(kwboot_baud_code_binhdr_pre) +
1520 sizeof(kwboot_baud_code) +
1521 sizeof(kwboot_baud_code_binhdr_post);
1522 code = kwboot_add_bin_ohdr_v1(img, size, codesz);
1524 codesz = sizeof(kwboot_baud_code_binhdr_pre);
1525 memcpy(code, kwboot_baud_code_binhdr_pre, codesz);
1529 codesz = sizeof(kwboot_baud_code) - 2 * sizeof(uint32_t);
1530 memcpy(code, kwboot_baud_code, codesz);
1532 *(uint32_t *)code = cpu_to_le32(old_baud);
1533 code += sizeof(uint32_t);
1534 *(uint32_t *)code = cpu_to_le32(new_baud);
1535 code += sizeof(uint32_t);
1538 codesz = sizeof(kwboot_baud_code_data_jump) - sizeof(uint32_t);
1539 memcpy(code, kwboot_baud_code_data_jump, codesz);
1541 *(uint32_t *)code = hdr->execaddr;
1542 code += sizeof(uint32_t);
1543 hdr->execaddr = cpu_to_le32(le32_to_cpu(hdr->destaddr) + orig_datasz);
1545 codesz = sizeof(kwboot_baud_code_binhdr_post);
1546 memcpy(code, kwboot_baud_code_binhdr_post, codesz);
1552 kwboot_img_patch(void *img, size_t *size, int baudrate)
1554 struct main_hdr_v1 *hdr;
1563 if (*size < sizeof(struct main_hdr_v1))
1566 image_ver = kwbimage_version(img);
1567 if (image_ver != 0 && image_ver != 1) {
1568 fprintf(stderr, "Invalid image header version\n");
1572 hdrsz = kwbheader_size(hdr);
1577 csum = kwboot_hdr_csum8(hdr) - hdr->checksum;
1578 if (csum != hdr->checksum)
1581 srcaddr = le32_to_cpu(hdr->srcaddr);
1583 switch (hdr->blockid) {
1584 case IBR_HDR_SATA_ID:
1588 hdr->srcaddr = cpu_to_le32((srcaddr - 1) * 512);
1591 case IBR_HDR_SDIO_ID:
1592 hdr->srcaddr = cpu_to_le32(srcaddr * 512);
1595 case IBR_HDR_PEX_ID:
1596 if (srcaddr == 0xFFFFFFFF)
1597 hdr->srcaddr = cpu_to_le32(hdrsz);
1600 case IBR_HDR_SPI_ID:
1601 if (hdr->destaddr == cpu_to_le32(0xFFFFFFFF)) {
1602 kwboot_printv("Patching destination and execution addresses from SPI/NOR XIP area to DDR area 0x00800000\n");
1603 hdr->destaddr = cpu_to_le32(0x00800000);
1604 hdr->execaddr = cpu_to_le32(0x00800000);
1609 if (hdrsz > le32_to_cpu(hdr->srcaddr) ||
1610 *size < le32_to_cpu(hdr->srcaddr) + le32_to_cpu(hdr->blocksize))
1613 if (kwboot_img_csum32(img) != *kwboot_img_csum32_ptr(img))
1616 is_secure = kwboot_img_is_secure(img);
1618 if (hdr->blockid != IBR_HDR_UART_ID) {
1621 "Image has secure header with signature for non-UART booting\n");
1625 kwboot_printv("Patching image boot signature to UART\n");
1626 hdr->blockid = IBR_HDR_UART_ID;
1630 if (image_ver == 1) {
1632 * Tell BootROM to send BootROM messages to UART port
1633 * number 0 (used also for UART booting) with default
1634 * baudrate (which should be 115200) and do not touch
1635 * UART MPP configuration.
1638 hdr->options &= ~0x1F;
1639 hdr->options |= MAIN_HDR_V1_OPT_BAUD_DEFAULT;
1640 hdr->options |= 0 << 3;
1643 ((struct main_hdr_v0 *)img)->nandeccmode = IBR_HDR_ECC_DISABLED;
1644 hdr->nandpagesize = 0;
1648 if (image_ver == 0) {
1650 "Cannot inject code for changing baudrate into v0 image header\n");
1656 "Cannot inject code for changing baudrate into image with secure header\n");
1661 * First inject code that changes the baudrate from the default
1662 * value of 115200 Bd to requested value. This code is inserted
1663 * as a new opt hdr, so it is executed by BootROM after the
1664 * header part is received.
1666 kwboot_printv("Injecting binary header code for changing baudrate to %d Bd\n",
1668 _inject_baudrate_change_code(img, size, 0, 115200, baudrate);
1671 * Now inject code that changes the baudrate back to 115200 Bd.
1672 * This code is appended after the data part of the image, and
1673 * execaddr is changed so that it is executed before U-Boot
1676 kwboot_printv("Injecting code for changing baudrate back\n");
1677 _inject_baudrate_change_code(img, size, 1, baudrate, 115200);
1679 /* Update the 32-bit data checksum */
1680 *kwboot_img_csum32_ptr(img) = kwboot_img_csum32(img);
1682 /* recompute header size */
1683 hdrsz = kwbheader_size(hdr);
1686 if (hdrsz % KWBOOT_XM_BLKSZ) {
1687 size_t grow = KWBOOT_XM_BLKSZ - hdrsz % KWBOOT_XM_BLKSZ;
1690 fprintf(stderr, "Cannot align image with secure header\n");
1694 kwboot_printv("Aligning image header to Xmodem block size\n");
1695 kwboot_img_grow_hdr(img, size, grow);
1698 hdr->checksum = kwboot_hdr_csum8(hdr) - csum;
1700 *size = le32_to_cpu(hdr->srcaddr) + le32_to_cpu(hdr->blocksize);
1708 kwboot_usage(FILE *stream, char *progname)
1711 "Usage: %s [OPTIONS] [-b <image> | -D <image> ] [-B <baud> ] <TTY>\n",
1713 fprintf(stream, "\n");
1715 " -b <image>: boot <image> with preamble (Kirkwood, Armada 370/XP)\n");
1717 " -D <image>: boot <image> without preamble (Dove)\n");
1718 fprintf(stream, " -d: enter debug mode\n");
1719 fprintf(stream, " -a: use timings for Armada XP\n");
1720 fprintf(stream, " -q <req-delay>: use specific request-delay\n");
1721 fprintf(stream, " -s <resp-timeo>: use specific response-timeout\n");
1723 " -o <block-timeo>: use specific xmodem block timeout\n");
1724 fprintf(stream, "\n");
1725 fprintf(stream, " -t: mini terminal\n");
1726 fprintf(stream, "\n");
1727 fprintf(stream, " -B <baud>: set baud rate\n");
1728 fprintf(stream, "\n");
1732 main(int argc, char **argv)
1734 const char *ttypath, *imgpath;
1735 int rv, rc, tty, term;
1740 size_t after_img_rsv;
1753 after_img_rsv = KWBOOT_XM_BLKSZ;
1756 printf("kwboot version %s\n", PLAIN_VERSION);
1758 kwboot_verbose = isatty(STDOUT_FILENO);
1761 prev_optind = optind;
1762 c = getopt(argc, argv, "hbptaB:dD:q:s:o:");
1768 if (imgpath || bootmsg || debugmsg)
1770 bootmsg = kwboot_msg_boot;
1771 if (prev_optind == optind)
1773 if (optind < argc - 1 && argv[optind] && argv[optind][0] != '-')
1774 imgpath = argv[optind++];
1778 if (imgpath || bootmsg || debugmsg)
1785 if (imgpath || bootmsg || debugmsg)
1787 debugmsg = kwboot_msg_debug;
1791 /* nop, for backward compatibility */
1799 msg_req_delay = KWBOOT_MSG_REQ_DELAY_AXP;
1800 msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO_AXP;
1804 msg_req_delay = atoi(optarg);
1808 msg_rsp_timeo = atoi(optarg);
1812 blk_rsp_timeo = atoi(optarg);
1816 baudrate = atoi(optarg);
1826 if (!bootmsg && !term && !debugmsg && !imgpath)
1829 ttypath = argv[optind++];
1834 tty = kwboot_open_tty(ttypath, imgpath ? 115200 : baudrate);
1840 if (baudrate == 115200)
1841 /* do not change baudrate during Xmodem to the same value */
1844 /* ensure we have enough space for baudrate change code */
1845 after_img_rsv += sizeof(struct opt_hdr_v1) + 8 + 16 +
1846 sizeof(kwboot_baud_code_binhdr_pre) +
1847 sizeof(kwboot_baud_code) +
1848 sizeof(kwboot_baud_code_binhdr_post) +
1850 sizeof(kwboot_baud_code) +
1851 sizeof(kwboot_baud_code_data_jump) +
1855 img = kwboot_read_image(imgpath, &size, after_img_rsv);
1861 rc = kwboot_img_patch(img, &size, baudrate);
1863 fprintf(stderr, "%s: Invalid image.\n", imgpath);
1869 rc = kwboot_debugmsg(tty, debugmsg);
1874 } else if (bootmsg) {
1875 rc = kwboot_bootmsg(tty, bootmsg);
1883 rc = kwboot_xmodem(tty, img, size, baudrate);
1891 rc = kwboot_terminal(tty);
1892 if (rc && !(errno == EINTR)) {
1909 kwboot_usage(rv ? stderr : stdout, basename(argv[0]));