2 * Boot a Marvell SoC, with Xmodem over UART0.
3 * supports Kirkwood, Dove, Armada 370, Armada XP
5 * (c) 2012 Daniel Stodden <daniel.stodden@gmail.com>
7 * References: marvell.com, "88F6180, 88F6190, 88F6192, and 88F6281
8 * Integrated Controller: Functional Specifications" December 2,
9 * 2008. Chapter 24.2 "BootROM Firmware".
30 #include "termios_linux.h"
36 * Marvell BootROM UART Sensing
39 static unsigned char kwboot_msg_boot[] = {
40 0xBB, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
43 static unsigned char kwboot_msg_debug[] = {
44 0xDD, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77
47 /* Defines known to work on Kirkwood */
48 #define KWBOOT_MSG_REQ_DELAY 10 /* ms */
49 #define KWBOOT_MSG_RSP_TIMEO 50 /* ms */
51 /* Defines known to work on Armada XP */
52 #define KWBOOT_MSG_REQ_DELAY_AXP 1000 /* ms */
53 #define KWBOOT_MSG_RSP_TIMEO_AXP 1000 /* ms */
59 #define SOH 1 /* sender start of block header */
60 #define EOT 4 /* sender end of block transfer */
61 #define ACK 6 /* target block ack */
62 #define NAK 21 /* target block negative ack */
63 #define CAN 24 /* target/sender transfer cancellation */
65 #define KWBOOT_XM_BLKSZ 128 /* xmodem block size */
71 uint8_t data[KWBOOT_XM_BLKSZ];
75 #define KWBOOT_BLK_RSP_TIMEO 1000 /* ms */
76 #define KWBOOT_HDR_RSP_TIMEO 10000 /* ms */
78 /* ARM code making baudrate changing function return to original exec address */
79 static unsigned char kwboot_pre_baud_code[] = {
81 0x00, 0x00, 0x00, 0x00, /* .word 0 */
82 0x0c, 0xe0, 0x1f, 0xe5, /* ldr lr, exec_addr */
85 /* ARM code for binary header injection to change baudrate */
86 static unsigned char kwboot_baud_code[] = {
87 /* ; #define UART_BASE 0xd0012000 */
88 /* ; #define THR 0x00 */
89 /* ; #define DLL 0x00 */
90 /* ; #define DLH 0x04 */
91 /* ; #define LCR 0x0c */
92 /* ; #define DLAB 0x80 */
93 /* ; #define LSR 0x14 */
94 /* ; #define THRE 0x20 */
95 /* ; #define TEMT 0x40 */
96 /* ; #define DIV_ROUND(a, b) ((a + b/2) / b) */
98 /* ; u32 set_baudrate(u32 old_b, u32 new_b) { */
99 /* ; const u8 *str = "$baudratechange"; */
103 /* ; writel(UART_BASE + THR, c); */
106 /* ; (!(readl(UART_BASE + LSR) & TEMT)); */
107 /* ; u32 lcr = readl(UART_BASE + LCR); */
108 /* ; writel(UART_BASE + LCR, lcr | DLAB); */
109 /* ; u8 old_dll = readl(UART_BASE + DLL); */
110 /* ; u8 old_dlh = readl(UART_BASE + DLH); */
111 /* ; u16 old_dl = old_dll | (old_dlh << 8); */
112 /* ; u32 clk = old_b * old_dl; */
113 /* ; u16 new_dl = DIV_ROUND(clk, new_b); */
114 /* ; u8 new_dll = new_dl & 0xff; */
115 /* ; u8 new_dlh = (new_dl >> 8) & 0xff; */
116 /* ; writel(UART_BASE + DLL, new_dll); */
117 /* ; writel(UART_BASE + DLH, new_dlh); */
118 /* ; writel(UART_BASE + LCR, lcr & ~DLAB); */
123 0xfe, 0x5f, 0x2d, 0xe9, /* push { r1 - r12, lr } */
125 /* ; r0 = UART_BASE */
126 0x02, 0x0a, 0xa0, 0xe3, /* mov r0, #0x2000 */
127 0x01, 0x00, 0x4d, 0xe3, /* movt r0, #0xd001 */
129 /* ; r2 = address of preamble string */
130 0xd0, 0x20, 0x8f, 0xe2, /* adr r2, preamble */
132 /* ; Send preamble string over UART */
133 /* .Lloop_preamble: */
135 /* ; Wait until Transmitter Holding is Empty */
137 /* ; r1 = UART_BASE[LSR] & THRE */
138 0x14, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x14] */
139 0x20, 0x00, 0x11, 0xe3, /* tst r1, #0x20 */
140 0xfc, 0xff, 0xff, 0x0a, /* beq .Lloop_thre */
142 /* ; Put character into Transmitter FIFO */
144 0x01, 0x10, 0xd2, 0xe4, /* ldrb r1, [r2], #1 */
145 /* ; UART_BASE[THR] = r1 */
146 0x00, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0] */
148 /* ; Loop until end of preamble string */
149 0x00, 0x00, 0x51, 0xe3, /* cmp r1, #0 */
150 0xf8, 0xff, 0xff, 0x1a, /* bne .Lloop_preamble */
152 /* ; Wait until Transmitter FIFO is Empty */
153 /* .Lloop_txempty: */
154 /* ; r1 = UART_BASE[LSR] & TEMT */
155 0x14, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x14] */
156 0x40, 0x00, 0x11, 0xe3, /* tst r1, #0x40 */
157 0xfc, 0xff, 0xff, 0x0a, /* beq .Lloop_txempty */
159 /* ; Set Divisor Latch Access Bit */
160 /* ; UART_BASE[LCR] |= DLAB */
161 0x0c, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x0c] */
162 0x80, 0x10, 0x81, 0xe3, /* orr r1, r1, #0x80 */
163 0x0c, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0c] */
165 /* ; Read current Divisor Latch */
166 /* ; r1 = UART_BASE[DLH]<<8 | UART_BASE[DLL] */
167 0x00, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x00] */
168 0xff, 0x10, 0x01, 0xe2, /* and r1, r1, #0xff */
169 0x01, 0x20, 0xa0, 0xe1, /* mov r2, r1 */
170 0x04, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x04] */
171 0xff, 0x10, 0x01, 0xe2, /* and r1, r1, #0xff */
172 0x41, 0x14, 0xa0, 0xe1, /* asr r1, r1, #8 */
173 0x02, 0x10, 0x81, 0xe1, /* orr r1, r1, r2 */
175 /* ; Read old baudrate value */
176 /* ; r2 = old_baudrate */
177 0x8c, 0x20, 0x9f, 0xe5, /* ldr r2, old_baudrate */
179 /* ; Calculate base clock */
181 0x92, 0x01, 0x01, 0xe0, /* mul r1, r2, r1 */
183 /* ; Read new baudrate value */
184 /* ; r2 = baudrate */
185 0x88, 0x20, 0x9f, 0xe5, /* ldr r2, baudrate */
187 /* ; Calculate new Divisor Latch */
188 /* ; r1 = DIV_ROUND(r1, r2) = */
189 /* ; = (r1 + r2/2) / r2 */
190 0xa2, 0x10, 0x81, 0xe0, /* add r1, r1, r2, lsr #1 */
191 0x02, 0x40, 0xa0, 0xe1, /* mov r4, r2 */
192 0xa1, 0x00, 0x54, 0xe1, /* cmp r4, r1, lsr #1 */
194 0x84, 0x40, 0xa0, 0x91, /* movls r4, r4, lsl #1 */
195 0xa1, 0x00, 0x54, 0xe1, /* cmp r4, r1, lsr #1 */
196 0xfc, 0xff, 0xff, 0x9a, /* bls .Lloop_div1 */
197 0x00, 0x30, 0xa0, 0xe3, /* mov r3, #0 */
199 0x04, 0x00, 0x51, 0xe1, /* cmp r1, r4 */
200 0x04, 0x10, 0x41, 0x20, /* subhs r1, r1, r4 */
201 0x03, 0x30, 0xa3, 0xe0, /* adc r3, r3, r3 */
202 0xa4, 0x40, 0xa0, 0xe1, /* mov r4, r4, lsr #1 */
203 0x02, 0x00, 0x54, 0xe1, /* cmp r4, r2 */
204 0xf9, 0xff, 0xff, 0x2a, /* bhs .Lloop_div2 */
205 0x03, 0x10, 0xa0, 0xe1, /* mov r1, r3 */
207 /* ; Set new Divisor Latch Low */
208 /* ; UART_BASE[DLL] = r1 & 0xff */
209 0x01, 0x20, 0xa0, 0xe1, /* mov r2, r1 */
210 0xff, 0x20, 0x02, 0xe2, /* and r2, r2, #0xff */
211 0x00, 0x20, 0x80, 0xe5, /* str r2, [r0, #0x00] */
213 /* ; Set new Divisor Latch High */
214 /* ; UART_BASE[DLH] = r1>>8 & 0xff */
215 0x41, 0x24, 0xa0, 0xe1, /* asr r2, r1, #8 */
216 0xff, 0x20, 0x02, 0xe2, /* and r2, r2, #0xff */
217 0x04, 0x20, 0x80, 0xe5, /* str r2, [r0, #0x04] */
219 /* ; Clear Divisor Latch Access Bit */
220 /* ; UART_BASE[LCR] &= ~DLAB */
221 0x0c, 0x10, 0x90, 0xe5, /* ldr r1, [r0, #0x0c] */
222 0x80, 0x10, 0xc1, 0xe3, /* bic r1, r1, #0x80 */
223 0x0c, 0x10, 0x80, 0xe5, /* str r1, [r0, #0x0c] */
225 /* ; Sleep 1ms ~~ 600000 cycles at 1200 MHz */
227 0x9f, 0x1d, 0xa0, 0xe3, /* mov r1, #0x27c0 */
228 0x09, 0x10, 0x40, 0xe3, /* movt r1, #0x0009 */
230 0x01, 0x10, 0x41, 0xe2, /* sub r1, r1, #1 */
231 0x00, 0x00, 0x51, 0xe3, /* cmp r1, #0 */
232 0xfc, 0xff, 0xff, 0x1a, /* bne .Lloop_sleep */
234 /* ; Return 0 - no error */
235 0x00, 0x00, 0xa0, 0xe3, /* mov r0, #0 */
236 0xfe, 0x9f, 0xbd, 0xe8, /* pop { r1 - r12, pc } */
238 /* ; Preamble string */
240 0x24, 0x62, 0x61, 0x75, /* .asciz "$baudratechange" */
241 0x64, 0x72, 0x61, 0x74,
242 0x65, 0x63, 0x68, 0x61,
243 0x6e, 0x67, 0x65, 0x00,
245 /* ; Placeholder for old baudrate value */
247 0x00, 0x00, 0x00, 0x00, /* .word 0 */
249 /* ; Placeholder for new baudrate value */
251 0x00, 0x00, 0x00, 0x00, /* .word 0 */
254 #define KWBOOT_BAUDRATE_BIN_HEADER_SZ (sizeof(kwboot_baud_code) + \
255 sizeof(struct opt_hdr_v1) + 8)
257 static const char kwb_baud_magic[16] = "$baudratechange";
259 static int kwboot_verbose;
261 static int msg_req_delay = KWBOOT_MSG_REQ_DELAY;
262 static int msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO;
263 static int blk_rsp_timeo = KWBOOT_BLK_RSP_TIMEO;
266 kwboot_write(int fd, const char *buf, size_t len)
271 ssize_t wr = write(fd, buf + tot, len - tot);
283 kwboot_printv(const char *fmt, ...)
287 if (kwboot_verbose) {
298 const char seq[] = { '-', '\\', '|', '/' };
300 static int state, bs;
302 if (state % div == 0) {
304 fputc(seq[state / div % sizeof(seq)], stdout);
320 __progress(int pct, char c)
322 const int width = 70;
323 static const char *nl = "";
326 if (pos % width == 0)
327 printf("%s%3d %% [", nl, pct);
332 pos = (pos + 1) % width;
335 while (pos && pos++ < width)
347 kwboot_progress(int _pct, char c)
362 kwboot_tty_recv(int fd, void *buf, size_t len, int timeo)
375 tv.tv_usec = timeo * 1000;
376 if (tv.tv_usec > 1000000) {
377 tv.tv_sec += tv.tv_usec / 1000000;
378 tv.tv_usec %= 1000000;
382 nfds = select(fd + 1, &rfds, NULL, NULL, &tv);
390 n = read(fd, buf, len);
394 buf = (char *)buf + n;
404 kwboot_tty_send(int fd, const void *buf, size_t len)
409 if (kwboot_write(fd, buf, len) < 0)
416 kwboot_tty_send_char(int fd, unsigned char c)
418 return kwboot_tty_send(fd, &c, 1);
422 kwboot_tty_baudrate_to_speed(int baudrate)
571 _is_within_tolerance(int value, int reference, int tolerance)
573 return 100 * value >= reference * (100 - tolerance) &&
574 100 * value <= reference * (100 + tolerance);
578 kwboot_tty_change_baudrate(int fd, int baudrate)
584 rc = tcgetattr(fd, &tio);
588 speed = kwboot_tty_baudrate_to_speed(baudrate);
596 tio.c_ospeed = tio.c_ispeed = baudrate;
599 rc = cfsetospeed(&tio, speed);
603 rc = cfsetispeed(&tio, speed);
607 rc = tcsetattr(fd, TCSANOW, &tio);
611 rc = tcgetattr(fd, &tio);
615 if (cfgetospeed(&tio) != speed || cfgetispeed(&tio) != speed)
620 * Check whether set baudrate is within 3% tolerance.
621 * If BOTHER is defined, Linux always fills out c_ospeed / c_ispeed
624 if (!_is_within_tolerance(tio.c_ospeed, baudrate, 3))
627 if (!_is_within_tolerance(tio.c_ispeed, baudrate, 3))
634 fprintf(stderr, "Could not set baudrate to requested value\n");
640 kwboot_open_tty(const char *path, int baudrate)
647 fd = open(path, O_RDWR|O_NOCTTY|O_NDELAY);
651 rc = tcgetattr(fd, &tio);
656 tio.c_cflag |= CREAD|CLOCAL;
660 rc = tcsetattr(fd, TCSANOW, &tio);
664 flags = fcntl(fd, F_GETFL);
668 rc = fcntl(fd, F_SETFL, flags & ~O_NDELAY);
672 rc = kwboot_tty_change_baudrate(fd, baudrate);
687 kwboot_bootmsg(int tty, void *msg)
694 kwboot_printv("Please reboot the target into UART boot mode...");
696 kwboot_printv("Sending boot message. Please reboot the target...");
699 rc = tcflush(tty, TCIOFLUSH);
703 for (count = 0; count < 128; count++) {
704 rc = kwboot_tty_send(tty, msg, 8);
706 usleep(msg_req_delay * 1000);
711 rc = kwboot_tty_recv(tty, &c, 1, msg_rsp_timeo);
715 } while (rc || c != NAK);
723 kwboot_debugmsg(int tty, void *msg)
727 kwboot_printv("Sending debug message. Please reboot the target...");
732 rc = tcflush(tty, TCIOFLUSH);
736 rc = kwboot_tty_send(tty, msg, 8);
738 usleep(msg_req_delay * 1000);
742 rc = kwboot_tty_recv(tty, buf, 16, msg_rsp_timeo);
754 kwboot_xm_makeblock(struct kwboot_block *block, const void *data,
755 size_t size, int pnum)
761 block->_pnum = ~block->pnum;
763 n = size < KWBOOT_XM_BLKSZ ? size : KWBOOT_XM_BLKSZ;
764 memcpy(&block->data[0], data, n);
765 memset(&block->data[n], 0, KWBOOT_XM_BLKSZ - n);
768 for (i = 0; i < n; i++)
769 block->csum += block->data[i];
779 if (clock_gettime(CLOCK_MONOTONIC, &ts)) {
780 static int err_print;
783 perror("clock_gettime() does not work");
787 /* this will just make the timeout not work */
791 return ts.tv_sec * 1000ULL + (ts.tv_nsec + 500000) / 1000000;
797 return c == ACK || c == NAK || c == CAN;
801 _xm_reply_to_error(int c)
824 kwboot_baud_magic_handle(int fd, char c, int baudrate)
826 static size_t rcv_len;
828 if (rcv_len < sizeof(kwb_baud_magic)) {
829 /* try to recognize whole magic word */
830 if (c == kwb_baud_magic[rcv_len]) {
833 printf("%.*s%c", (int)rcv_len, kwb_baud_magic, c);
839 if (rcv_len == sizeof(kwb_baud_magic)) {
840 /* magic word received */
841 kwboot_printv("\nChanging baudrate to %d Bd\n", baudrate);
843 return kwboot_tty_change_baudrate(fd, baudrate) ? : 1;
850 kwboot_xm_recv_reply(int fd, char *c, int allow_non_xm, int *non_xm_print,
851 int baudrate, int *baud_changed)
853 int timeout = allow_non_xm ? KWBOOT_HDR_RSP_TIMEO : blk_rsp_timeo;
854 uint64_t recv_until = _now() + timeout;
863 rc = kwboot_tty_recv(fd, c, 1, timeout);
865 if (errno != ETIMEDOUT)
867 else if (allow_non_xm && *non_xm_print)
873 /* If received xmodem reply, end. */
874 if (_is_xm_reply(*c))
878 * If receiving/printing non-xmodem text output is allowed and
879 * such a byte was received, we want to increase receiving time
881 * - print the byte, if it is not part of baudrate change magic
882 * sequence while baudrate change was requested (-B option)
884 * Otherwise decrease timeout by time elapsed.
887 recv_until = _now() + timeout;
889 if (baudrate && !*baud_changed) {
890 rc = kwboot_baud_magic_handle(fd, *c, baudrate);
897 } else if (!baudrate || !*baud_changed) {
903 timeout = recv_until - _now();
915 kwboot_xm_sendblock(int fd, struct kwboot_block *block, int allow_non_xm,
916 int *done_print, int baudrate)
918 int non_xm_print, baud_changed;
919 int rc, err, retries;
926 rc = kwboot_tty_send(fd, block, sizeof(*block));
930 if (allow_non_xm && !*done_print) {
931 kwboot_progress(100, '.');
932 kwboot_printv("Done\n");
936 rc = kwboot_xm_recv_reply(fd, &c, allow_non_xm, &non_xm_print,
937 baudrate, &baud_changed);
941 if (!allow_non_xm && c != ACK)
942 kwboot_progress(-1, '+');
943 } while (c == NAK && retries-- > 0);
948 if (allow_non_xm && baudrate && !baud_changed) {
949 fprintf(stderr, "Baudrate was not changed\n");
955 return _xm_reply_to_error(c);
958 kwboot_tty_send_char(fd, CAN);
965 kwboot_xm_finish(int fd)
970 kwboot_printv("Finishing transfer\n");
974 rc = kwboot_tty_send_char(fd, EOT);
978 rc = kwboot_xm_recv_reply(fd, &c, 0, NULL, 0, NULL);
981 } while (c == NAK && retries-- > 0);
983 return _xm_reply_to_error(c);
987 kwboot_xmodem_one(int tty, int *pnum, int header, const uint8_t *data,
988 size_t size, int baudrate)
994 kwboot_printv("Sending boot image %s (%zu bytes)...\n",
995 header ? "header" : "data", size);
1000 while (sent < size) {
1001 struct kwboot_block block;
1005 blksz = kwboot_xm_makeblock(&block, data, left, (*pnum)++);
1008 last_block = (left <= blksz);
1010 rc = kwboot_xm_sendblock(tty, &block, header && last_block,
1011 &done_print, baudrate);
1019 kwboot_progress(sent * 100 / size, '.');
1023 kwboot_printv("Done\n");
1027 kwboot_printv("\n");
1032 kwboot_xmodem(int tty, const void *_img, size_t size, int baudrate)
1034 const uint8_t *img = _img;
1038 hdrsz = kwbheader_size(img);
1040 kwboot_printv("Waiting 2s and flushing tty\n");
1041 sleep(2); /* flush isn't effective without it */
1042 tcflush(tty, TCIOFLUSH);
1046 rc = kwboot_xmodem_one(tty, &pnum, 1, img, hdrsz, baudrate);
1053 rc = kwboot_xmodem_one(tty, &pnum, 0, img, size, 0);
1057 rc = kwboot_xm_finish(tty);
1062 char buf[sizeof(kwb_baud_magic)];
1064 /* Wait 1s for baudrate change magic */
1065 rc = kwboot_tty_recv(tty, buf, sizeof(buf), 1000);
1069 if (memcmp(buf, kwb_baud_magic, sizeof(buf))) {
1074 kwboot_printv("\nChanging baudrate back to 115200 Bd\n\n");
1075 rc = kwboot_tty_change_baudrate(tty, 115200);
1084 kwboot_term_pipe(int in, int out, const char *quit, int *s)
1087 char _buf[128], *buf = _buf;
1089 nin = read(in, buf, sizeof(_buf));
1096 for (i = 0; i < nin; i++) {
1097 if (*buf == quit[*s]) {
1104 if (kwboot_write(out, quit, *s) < 0)
1111 if (kwboot_write(out, buf, nin) < 0)
1118 kwboot_terminal(int tty)
1121 const char *quit = "\34c";
1122 struct termios otio, tio;
1128 rc = tcgetattr(in, &otio);
1132 rc = tcsetattr(in, TCSANOW, &tio);
1135 perror("tcsetattr");
1139 kwboot_printv("[Type Ctrl-%c + %c to quit]\r\n",
1140 quit[0]|0100, quit[1]);
1152 nfds = nfds < tty ? tty : nfds;
1156 nfds = nfds < in ? in : nfds;
1159 nfds = select(nfds + 1, &rfds, NULL, NULL, NULL);
1163 if (FD_ISSET(tty, &rfds)) {
1164 rc = kwboot_term_pipe(tty, STDOUT_FILENO, NULL, NULL);
1169 if (in >= 0 && FD_ISSET(in, &rfds)) {
1170 rc = kwboot_term_pipe(in, tty, quit, &s);
1174 } while (quit[s] != 0);
1177 tcsetattr(in, TCSANOW, &otio);
1184 kwboot_read_image(const char *path, size_t *size, size_t reserve)
1194 fd = open(path, O_RDONLY);
1198 rc = fstat(fd, &st);
1202 img = malloc(st.st_size + reserve);
1207 while (tot < st.st_size) {
1208 ssize_t rd = read(fd, img + tot, st.st_size - tot);
1215 if (!rd && tot < st.st_size) {
1235 kwboot_hdr_csum8(const void *hdr)
1237 const uint8_t *data = hdr;
1241 size = kwbheader_size_for_csum(hdr);
1243 for (csum = 0; size-- > 0; data++)
1250 kwboot_img_is_secure(void *img)
1252 struct opt_hdr_v1 *ohdr;
1254 for_each_opt_hdr_v1 (ohdr, img)
1255 if (ohdr->headertype == OPT_HDR_V1_SECURE_TYPE)
1262 kwboot_img_grow_data_left(void *img, size_t *size, size_t grow)
1264 uint32_t hdrsz, datasz, srcaddr;
1265 struct main_hdr_v1 *hdr = img;
1268 srcaddr = le32_to_cpu(hdr->srcaddr);
1270 hdrsz = kwbheader_size(hdr);
1271 data = (uint8_t *)img + srcaddr;
1272 datasz = *size - srcaddr;
1274 /* only move data if there is not enough space */
1275 if (hdrsz + grow > srcaddr) {
1276 size_t need = hdrsz + grow - srcaddr;
1278 /* move data by enough bytes */
1279 memmove(data + need, data, datasz);
1285 hdr->srcaddr = cpu_to_le32(srcaddr);
1286 hdr->destaddr = cpu_to_le32(le32_to_cpu(hdr->destaddr) - grow);
1287 hdr->blocksize = cpu_to_le32(le32_to_cpu(hdr->blocksize) + grow);
1289 return (uint8_t *)img + srcaddr;
1293 kwboot_img_grow_hdr(void *img, size_t *size, size_t grow)
1295 uint32_t hdrsz, datasz, srcaddr;
1296 struct main_hdr_v1 *hdr = img;
1299 srcaddr = le32_to_cpu(hdr->srcaddr);
1301 hdrsz = kwbheader_size(img);
1302 data = (uint8_t *)img + srcaddr;
1303 datasz = *size - srcaddr;
1305 /* only move data if there is not enough space */
1306 if (hdrsz + grow > srcaddr) {
1307 size_t need = hdrsz + grow - srcaddr;
1309 /* move data by enough bytes */
1310 memmove(data + need, data, datasz);
1312 hdr->srcaddr = cpu_to_le32(srcaddr + need);
1316 if (kwbimage_version(img) == 1) {
1318 hdr->headersz_msb = hdrsz >> 16;
1319 hdr->headersz_lsb = cpu_to_le16(hdrsz & 0xffff);
1324 kwboot_add_bin_ohdr_v1(void *img, size_t *size, uint32_t binsz)
1326 struct main_hdr_v1 *hdr = img;
1327 struct opt_hdr_v1 *ohdr;
1330 ohdrsz = binsz + 8 + sizeof(*ohdr);
1331 kwboot_img_grow_hdr(img, size, ohdrsz);
1333 if (hdr->ext & 0x1) {
1334 for_each_opt_hdr_v1 (ohdr, img)
1335 if (opt_hdr_v1_next(ohdr) == NULL)
1338 *opt_hdr_v1_ext(ohdr) |= 1;
1339 ohdr = opt_hdr_v1_next(ohdr);
1342 ohdr = (void *)(hdr + 1);
1345 ohdr->headertype = OPT_HDR_V1_BINARY_TYPE;
1346 ohdr->headersz_msb = ohdrsz >> 16;
1347 ohdr->headersz_lsb = cpu_to_le16(ohdrsz & 0xffff);
1349 memset(&ohdr->data[0], 0, ohdrsz - sizeof(*ohdr));
1351 return &ohdr->data[4];
1355 _copy_baudrate_change_code(struct main_hdr_v1 *hdr, void *dst, int pre,
1356 int old_baud, int new_baud)
1358 size_t codesz = sizeof(kwboot_baud_code);
1359 uint8_t *code = dst;
1362 size_t presz = sizeof(kwboot_pre_baud_code);
1365 * We need to prepend code that loads lr register with original
1366 * value of hdr->execaddr. We do this by putting the original
1367 * exec address before the code that loads it relatively from
1369 * Afterwards we change the exec address to this code (which is
1370 * at offset 4, because the first 4 bytes contain the original
1373 memcpy(code, kwboot_pre_baud_code, presz);
1374 *(uint32_t *)code = hdr->execaddr;
1376 hdr->execaddr = cpu_to_le32(le32_to_cpu(hdr->destaddr) + 4);
1381 memcpy(code, kwboot_baud_code, codesz - 8);
1382 *(uint32_t *)(code + codesz - 8) = cpu_to_le32(old_baud);
1383 *(uint32_t *)(code + codesz - 4) = cpu_to_le32(new_baud);
1387 kwboot_img_patch(void *img, size_t *size, int baudrate)
1390 struct main_hdr_v1 *hdr;
1400 if (*size < sizeof(struct main_hdr_v1)) {
1405 image_ver = kwbimage_version(img);
1406 if (image_ver != 0 && image_ver != 1) {
1407 fprintf(stderr, "Invalid image header version\n");
1412 hdrsz = kwbheader_size(hdr);
1414 if (*size < hdrsz) {
1419 csum = kwboot_hdr_csum8(hdr) - hdr->checksum;
1420 if (csum != hdr->checksum) {
1425 if (image_ver == 0) {
1426 struct main_hdr_v0 *hdr_v0 = img;
1428 hdr_v0->nandeccmode = IBR_HDR_ECC_DISABLED;
1429 hdr_v0->nandpagesize = 0;
1432 srcaddr = le32_to_cpu(hdr->srcaddr);
1434 switch (hdr->blockid) {
1435 case IBR_HDR_SATA_ID:
1440 hdr->srcaddr = cpu_to_le32((srcaddr - 1) * 512);
1443 case IBR_HDR_SDIO_ID:
1444 hdr->srcaddr = cpu_to_le32(srcaddr * 512);
1447 case IBR_HDR_PEX_ID:
1448 if (srcaddr == 0xFFFFFFFF)
1449 hdr->srcaddr = cpu_to_le32(hdrsz);
1452 case IBR_HDR_SPI_ID:
1453 if (hdr->destaddr == cpu_to_le32(0xFFFFFFFF)) {
1454 kwboot_printv("Patching destination and execution addresses from SPI/NOR XIP area to DDR area 0x00800000\n");
1455 hdr->destaddr = cpu_to_le32(0x00800000);
1456 hdr->execaddr = cpu_to_le32(0x00800000);
1461 if (hdrsz > le32_to_cpu(hdr->srcaddr) ||
1462 *size < le32_to_cpu(hdr->srcaddr) + le32_to_cpu(hdr->blocksize)) {
1467 is_secure = kwboot_img_is_secure(img);
1469 if (hdr->blockid != IBR_HDR_UART_ID) {
1472 "Image has secure header with signature for non-UART booting\n");
1477 kwboot_printv("Patching image boot signature to UART\n");
1478 hdr->blockid = IBR_HDR_UART_ID;
1482 uint32_t codesz = sizeof(kwboot_baud_code);
1485 if (image_ver == 0) {
1487 "Cannot inject code for changing baudrate into v0 image header\n");
1494 "Cannot inject code for changing baudrate into image with secure header\n");
1500 * First inject code that changes the baudrate from the default
1501 * value of 115200 Bd to requested value. This code is inserted
1502 * as a new opt hdr, so it is executed by BootROM after the
1503 * header part is received.
1505 kwboot_printv("Injecting binary header code for changing baudrate to %d Bd\n",
1508 code = kwboot_add_bin_ohdr_v1(img, size, codesz);
1509 _copy_baudrate_change_code(hdr, code, 0, 115200, baudrate);
1512 * Now inject code that changes the baudrate back to 115200 Bd.
1513 * This code is prepended to the data part of the image, so it
1514 * is executed before U-Boot proper.
1516 kwboot_printv("Injecting code for changing baudrate back\n");
1518 codesz += sizeof(kwboot_pre_baud_code);
1519 code = kwboot_img_grow_data_left(img, size, codesz);
1520 _copy_baudrate_change_code(hdr, code, 1, baudrate, 115200);
1522 /* recompute header size */
1523 hdrsz = kwbheader_size(hdr);
1526 if (hdrsz % KWBOOT_XM_BLKSZ) {
1527 size_t offset = (KWBOOT_XM_BLKSZ - hdrsz % KWBOOT_XM_BLKSZ) %
1531 fprintf(stderr, "Cannot align image with secure header\n");
1536 kwboot_printv("Aligning image header to Xmodem block size\n");
1537 kwboot_img_grow_hdr(img, size, offset);
1540 hdr->checksum = kwboot_hdr_csum8(hdr) - csum;
1542 *size = le32_to_cpu(hdr->srcaddr) + le32_to_cpu(hdr->blocksize);
1549 kwboot_usage(FILE *stream, char *progname)
1551 fprintf(stream, "kwboot version %s\n", PLAIN_VERSION);
1553 "Usage: %s [OPTIONS] [-b <image> | -D <image> ] [-B <baud> ] <TTY>\n",
1555 fprintf(stream, "\n");
1557 " -b <image>: boot <image> with preamble (Kirkwood, Armada 370/XP)\n");
1559 " -D <image>: boot <image> without preamble (Dove)\n");
1560 fprintf(stream, " -d: enter debug mode\n");
1561 fprintf(stream, " -a: use timings for Armada XP\n");
1562 fprintf(stream, " -q <req-delay>: use specific request-delay\n");
1563 fprintf(stream, " -s <resp-timeo>: use specific response-timeout\n");
1565 " -o <block-timeo>: use specific xmodem block timeout\n");
1566 fprintf(stream, "\n");
1567 fprintf(stream, " -t: mini terminal\n");
1568 fprintf(stream, "\n");
1569 fprintf(stream, " -B <baud>: set baud rate\n");
1570 fprintf(stream, "\n");
1574 main(int argc, char **argv)
1576 const char *ttypath, *imgpath;
1577 int rv, rc, tty, term;
1582 size_t after_img_rsv;
1593 after_img_rsv = KWBOOT_XM_BLKSZ;
1596 kwboot_verbose = isatty(STDOUT_FILENO);
1599 int c = getopt(argc, argv, "hb:ptaB:dD:q:s:o:");
1605 bootmsg = kwboot_msg_boot;
1615 debugmsg = kwboot_msg_debug;
1619 /* nop, for backward compatibility */
1627 msg_req_delay = KWBOOT_MSG_REQ_DELAY_AXP;
1628 msg_rsp_timeo = KWBOOT_MSG_RSP_TIMEO_AXP;
1632 msg_req_delay = atoi(optarg);
1636 msg_rsp_timeo = atoi(optarg);
1640 blk_rsp_timeo = atoi(optarg);
1644 baudrate = atoi(optarg);
1654 if (!bootmsg && !term && !debugmsg)
1657 if (argc - optind < 1)
1660 ttypath = argv[optind++];
1662 tty = kwboot_open_tty(ttypath, imgpath ? 115200 : baudrate);
1668 if (baudrate == 115200)
1669 /* do not change baudrate during Xmodem to the same value */
1672 /* ensure we have enough space for baudrate change code */
1673 after_img_rsv += KWBOOT_BAUDRATE_BIN_HEADER_SZ +
1674 sizeof(kwboot_pre_baud_code) +
1675 sizeof(kwboot_baud_code);
1678 img = kwboot_read_image(imgpath, &size, after_img_rsv);
1684 rc = kwboot_img_patch(img, &size, baudrate);
1686 fprintf(stderr, "%s: Invalid image.\n", imgpath);
1692 rc = kwboot_debugmsg(tty, debugmsg);
1697 } else if (bootmsg) {
1698 rc = kwboot_bootmsg(tty, bootmsg);
1706 rc = kwboot_xmodem(tty, img, size, baudrate);
1714 rc = kwboot_terminal(tty);
1715 if (rc && !(errno == EINTR)) {
1732 kwboot_usage(rv ? stderr : stdout, basename(argv[0]));