2 * Boot a Marvell SoC, with Xmodem over UART0.
3 * supports Kirkwood, Dove, Armada 370, Armada XP
5 * (c) 2012 Daniel Stodden <daniel.stodden@gmail.com>
7 * References: marvell.com, "88F6180, 88F6190, 88F6192, and 88F6281
8 * Integrated Controller: Functional Specifications" December 2,
9 * 2008. Chapter 24.2 "BootROM Firmware".
31 * Marvell BootROM UART Sensing
34 static unsigned char kwboot_msg_boot[] = {
35 0xBB, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
38 static unsigned char kwboot_msg_debug[] = {
39 0xDD, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
42 /* Defines known to work on Kirkwood */
43 #define KWBOOT_MSG_REQ_DELAY 10 /* ms */
44 #define KWBOOT_MSG_RSP_TIMEO 50 /* ms */
46 /* Defines known to work on Armada XP */
47 #define KWBOOT_MSG_REQ_DELAY_AXP 1000 /* ms */
48 #define KWBOOT_MSG_RSP_TIMEO_AXP 1000 /* ms */
54 #define SOH 1 /* sender start of block header */
55 #define EOT 4 /* sender end of block transfer */
56 #define ACK 6 /* target block ack */
57 #define NAK 21 /* target block negative ack */
58 #define CAN 24 /* target/sender transfer cancellation */
60 #define KWBOOT_XM_BLKSZ 128 /* xmodem block size */
66 uint8_t data[KWBOOT_XM_BLKSZ];
70 #define KWBOOT_BLK_RSP_TIMEO 1000 /* ms */
72 static int kwboot_verbose;
74 static int msg_req_delay = KWBOOT_MSG_REQ_DELAY;
75 static int msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO;
76 static int blk_rsp_timeo = KWBOOT_BLK_RSP_TIMEO;
79 kwboot_write(int fd, const char *buf, size_t len)
84 ssize_t wr = write(fd, buf + tot, len - tot);
96 kwboot_printv(const char *fmt, ...)
100 if (kwboot_verbose) {
111 const char seq[] = { '-', '\\', '|', '/' };
113 static int state, bs;
115 if (state % div == 0) {
117 fputc(seq[state / div % sizeof(seq)], stdout);
133 __progress(int pct, char c)
135 const int width = 70;
136 static const char *nl = "";
139 if (pos % width == 0)
140 printf("%s%3d %% [", nl, pct);
145 pos = (pos + 1) % width;
148 while (pos && pos++ < width)
160 kwboot_progress(int _pct, char c)
175 kwboot_tty_recv(int fd, void *buf, size_t len, int timeo)
188 tv.tv_usec = timeo * 1000;
189 if (tv.tv_usec > 1000000) {
190 tv.tv_sec += tv.tv_usec / 1000000;
191 tv.tv_usec %= 1000000;
195 nfds = select(fd + 1, &rfds, NULL, NULL, &tv);
203 n = read(fd, buf, len);
207 buf = (char *)buf + n;
217 kwboot_tty_send(int fd, const void *buf, size_t len)
222 if (kwboot_write(fd, buf, len) < 0)
229 kwboot_tty_send_char(int fd, unsigned char c)
231 return kwboot_tty_send(fd, &c, 1);
235 kwboot_tty_speed(int baudrate)
254 kwboot_open_tty(const char *path, speed_t speed)
261 fd = open(path, O_RDWR|O_NOCTTY|O_NDELAY);
265 memset(&tio, 0, sizeof(tio));
268 tio.c_cflag = CREAD|CLOCAL|CS8;
271 tio.c_cc[VTIME] = 10;
273 cfsetospeed(&tio, speed);
274 cfsetispeed(&tio, speed);
276 rc = tcsetattr(fd, TCSANOW, &tio);
291 kwboot_bootmsg(int tty, void *msg)
298 kwboot_printv("Please reboot the target into UART boot mode...");
300 kwboot_printv("Sending boot message. Please reboot the target...");
303 rc = tcflush(tty, TCIOFLUSH);
307 for (count = 0; count < 128; count++) {
308 rc = kwboot_tty_send(tty, msg, 8);
310 usleep(msg_req_delay * 1000);
315 rc = kwboot_tty_recv(tty, &c, 1, msg_rsp_timeo);
319 } while (rc || c != NAK);
327 kwboot_debugmsg(int tty, void *msg)
331 kwboot_printv("Sending debug message. Please reboot the target...");
336 rc = tcflush(tty, TCIOFLUSH);
340 rc = kwboot_tty_send(tty, msg, 8);
342 usleep(msg_req_delay * 1000);
346 rc = kwboot_tty_recv(tty, buf, 16, msg_rsp_timeo);
358 kwboot_xm_makeblock(struct kwboot_block *block, const void *data,
359 size_t size, int pnum)
365 block->_pnum = ~block->pnum;
367 n = size < KWBOOT_XM_BLKSZ ? size : KWBOOT_XM_BLKSZ;
368 memcpy(&block->data[0], data, n);
369 memset(&block->data[n], 0, KWBOOT_XM_BLKSZ - n);
372 for (i = 0; i < n; i++)
373 block->csum += block->data[i];
379 kwboot_xm_sendblock(int fd, struct kwboot_block *block)
386 rc = kwboot_tty_send(fd, block, sizeof(*block));
391 rc = kwboot_tty_recv(fd, &c, 1, blk_rsp_timeo);
393 if (errno != ETIMEDOUT)
398 if (c != ACK && c != NAK && c != CAN)
401 } while (c != ACK && c != NAK && c != CAN);
404 kwboot_progress(-1, '+');
406 } while (c == NAK && retries-- > 0);
429 kwboot_xmodem_one(int tty, int *pnum, int header, const uint8_t *data,
435 kwboot_printv("Sending boot image %s (%zu bytes)...\n",
436 header ? "header" : "data", size);
441 while (sent < size) {
442 struct kwboot_block block;
445 blksz = kwboot_xm_makeblock(&block, data, left, (*pnum)++);
448 rc = kwboot_xm_sendblock(tty, &block);
455 kwboot_progress(sent * 100 / size, '.');
458 kwboot_printv("Done\n");
467 kwboot_xmodem(int tty, const void *_img, size_t size)
469 const uint8_t *img = _img;
473 if (image_version(img) == 0)
474 hdrsz = KWBHEADER_V0_SIZE((struct main_hdr_v0 *)img);
476 hdrsz = KWBHEADER_V1_SIZE((struct main_hdr_v1 *)img);
478 kwboot_printv("Waiting 2s and flushing tty\n");
479 sleep(2); /* flush isn't effective without it */
480 tcflush(tty, TCIOFLUSH);
484 rc = kwboot_xmodem_one(tty, &pnum, 1, img, hdrsz);
491 rc = kwboot_xmodem_one(tty, &pnum, 0, img, size);
495 return kwboot_tty_send_char(tty, EOT);
499 kwboot_term_pipe(int in, int out, const char *quit, int *s)
502 char _buf[128], *buf = _buf;
504 nin = read(in, buf, sizeof(_buf));
511 for (i = 0; i < nin; i++) {
512 if (*buf == quit[*s]) {
519 if (kwboot_write(out, quit, *s) < 0)
526 if (kwboot_write(out, buf, nin) < 0)
533 kwboot_terminal(int tty)
536 const char *quit = "\34c";
537 struct termios otio, tio;
543 rc = tcgetattr(in, &otio);
547 rc = tcsetattr(in, TCSANOW, &tio);
554 kwboot_printv("[Type Ctrl-%c + %c to quit]\r\n",
555 quit[0]|0100, quit[1]);
567 nfds = nfds < tty ? tty : nfds;
571 nfds = nfds < in ? in : nfds;
574 nfds = select(nfds + 1, &rfds, NULL, NULL, NULL);
578 if (FD_ISSET(tty, &rfds)) {
579 rc = kwboot_term_pipe(tty, STDOUT_FILENO, NULL, NULL);
584 if (in >= 0 && FD_ISSET(in, &rfds)) {
585 rc = kwboot_term_pipe(in, tty, quit, &s);
589 } while (quit[s] != 0);
592 tcsetattr(in, TCSANOW, &otio);
599 kwboot_mmap_image(const char *path, size_t *size, int prot)
608 fd = open(path, O_RDONLY);
616 flags = (prot & PROT_WRITE) ? MAP_PRIVATE : MAP_SHARED;
618 img = mmap(NULL, st.st_size, prot, flags, fd, 0);
619 if (img == MAP_FAILED) {
628 munmap(img, st.st_size);
638 kwboot_img_csum8(void *_data, size_t size)
640 uint8_t *data = _data, csum;
642 for (csum = 0; size-- > 0; data++)
649 kwboot_img_patch_hdr(void *img, size_t size)
652 struct main_hdr_v1 *hdr;
654 size_t hdrsz = sizeof(*hdr);
665 image_ver = image_version(img);
666 if (image_ver != 0 && image_ver != 1) {
667 fprintf(stderr, "Invalid image header version\n");
673 hdrsz = sizeof(*hdr);
675 hdrsz = KWBHEADER_V1_SIZE(hdr);
682 csum = kwboot_img_csum8(hdr, hdrsz) - hdr->checksum;
683 if (csum != hdr->checksum) {
688 if (hdr->blockid == IBR_HDR_UART_ID) {
693 hdr->blockid = IBR_HDR_UART_ID;
695 if (image_ver == 0) {
696 struct main_hdr_v0 *hdr_v0 = img;
698 hdr_v0->nandeccmode = IBR_HDR_ECC_DISABLED;
699 hdr_v0->nandpagesize = 0;
701 hdr_v0->srcaddr = hdr_v0->ext
702 ? sizeof(struct kwb_header)
706 hdr->checksum = kwboot_img_csum8(hdr, hdrsz) - csum;
714 kwboot_usage(FILE *stream, char *progname)
716 fprintf(stream, "kwboot version %s\n", PLAIN_VERSION);
718 "Usage: %s [OPTIONS] [-b <image> | -D <image> ] [-B <baud> ] <TTY>\n",
720 fprintf(stream, "\n");
722 " -b <image>: boot <image> with preamble (Kirkwood, Armada 370/XP)\n");
723 fprintf(stream, " -p: patch <image> to type 0x69 (uart boot)\n");
725 " -D <image>: boot <image> without preamble (Dove)\n");
726 fprintf(stream, " -d: enter debug mode\n");
727 fprintf(stream, " -a: use timings for Armada XP\n");
728 fprintf(stream, " -q <req-delay>: use specific request-delay\n");
729 fprintf(stream, " -s <resp-timeo>: use specific response-timeout\n");
731 " -o <block-timeo>: use specific xmodem block timeout\n");
732 fprintf(stream, "\n");
733 fprintf(stream, " -t: mini terminal\n");
734 fprintf(stream, "\n");
735 fprintf(stream, " -B <baud>: set baud rate\n");
736 fprintf(stream, "\n");
740 main(int argc, char **argv)
742 const char *ttypath, *imgpath;
743 int rv, rc, tty, term, prot, patch;
761 kwboot_verbose = isatty(STDOUT_FILENO);
764 int c = getopt(argc, argv, "hb:ptaB:dD:q:s:o:");
770 bootmsg = kwboot_msg_boot;
780 debugmsg = kwboot_msg_debug;
792 msg_req_delay = KWBOOT_MSG_REQ_DELAY_AXP;
793 msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO_AXP;
797 msg_req_delay = atoi(optarg);
801 msg_rsp_timeo = atoi(optarg);
805 blk_rsp_timeo = atoi(optarg);
809 speed = kwboot_tty_speed(atoi(optarg));
821 if (!bootmsg && !term && !debugmsg)
824 if (patch && !imgpath)
827 if (argc - optind < 1)
830 ttypath = argv[optind++];
832 tty = kwboot_open_tty(ttypath, speed);
839 prot = PROT_READ | (patch ? PROT_WRITE : 0);
841 img = kwboot_mmap_image(imgpath, &size, prot);
849 rc = kwboot_img_patch_hdr(img, size);
851 fprintf(stderr, "%s: Invalid image.\n", imgpath);
857 rc = kwboot_debugmsg(tty, debugmsg);
862 } else if (bootmsg) {
863 rc = kwboot_bootmsg(tty, bootmsg);
871 rc = kwboot_xmodem(tty, img, size);
879 rc = kwboot_terminal(tty);
880 if (rc && !(errno == EINTR)) {
897 kwboot_usage(rv ? stderr : stdout, basename(argv[0]));