esp_loader.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. /* Copyright 2020-2023 Espressif Systems (Shanghai) CO LTD
  2. *
  3. * Licensed under the Apache License, Version 2.0 (the "License");
  4. * you may not use this file except in compliance with the License.
  5. * You may obtain a copy of the License at
  6. *
  7. * http://www.apache.org/licenses/LICENSE-2.0
  8. *
  9. * Unless required by applicable law or agreed to in writing, software
  10. * distributed under the License is distributed on an "AS IS" BASIS,
  11. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. * See the License for the specific language governing permissions and
  13. * limitations under the License.
  14. */
  15. #include "protocol.h"
  16. #include "esp_loader_io.h"
  17. #include "esp_loader.h"
  18. #include "esp_targets.h"
  19. #include "md5_hash.h"
  20. #include <string.h>
  21. #include <assert.h>
  22. #ifndef MAX
  23. #define MAX(a, b) ((a) > (b)) ? (a) : (b)
  24. #endif
  25. #ifndef MIN
  26. #define MIN(a, b) ((a) < (b)) ? (a) : (b)
  27. #endif
  28. #ifndef ROUNDUP
  29. #define ROUNDUP(a, b) (((int)a + (int)b - 1) / (int)b)
  30. #endif
  31. static const uint32_t DEFAULT_TIMEOUT = 1000;
  32. static const uint32_t DEFAULT_FLASH_TIMEOUT = 3000; // timeout for most flash operations
  33. static const uint32_t LOAD_RAM_TIMEOUT_PER_MB = 2000000; // timeout (per megabyte) for erasing a region
  34. typedef enum {
  35. SPI_FLASH_READ_ID = 0x9F
  36. } spi_flash_cmd_t;
  37. static const target_registers_t *s_reg = NULL;
  38. static target_chip_t s_target = ESP_UNKNOWN_CHIP;
  39. #if MD5_ENABLED
  40. static const uint32_t MD5_TIMEOUT_PER_MB = 800;
  41. static struct MD5Context s_md5_context;
  42. static uint32_t s_start_address;
  43. static uint32_t s_image_size;
  44. static inline void init_md5(uint32_t address, uint32_t size)
  45. {
  46. s_start_address = address;
  47. s_image_size = size;
  48. MD5Init(&s_md5_context);
  49. }
  50. static inline void md5_update(const uint8_t *data, uint32_t size)
  51. {
  52. MD5Update(&s_md5_context, data, size);
  53. }
  54. static inline void md5_final(uint8_t digets[16])
  55. {
  56. MD5Final(digets, &s_md5_context);
  57. }
  58. #else
  59. static inline void init_md5(uint32_t address, uint32_t size) { }
  60. static inline void md5_update(const uint8_t *data, uint32_t size) { }
  61. static inline void md5_final(uint8_t digets[16]) { }
  62. #endif
  63. static uint32_t timeout_per_mb(uint32_t size_bytes, uint32_t time_per_mb)
  64. {
  65. uint32_t timeout = time_per_mb * (size_bytes / 1e6);
  66. return MAX(timeout, DEFAULT_FLASH_TIMEOUT);
  67. }
  68. esp_loader_error_t esp_loader_connect(esp_loader_connect_args_t *connect_args)
  69. {
  70. loader_port_enter_bootloader();
  71. RETURN_ON_ERROR(loader_initialize_conn(connect_args));
  72. RETURN_ON_ERROR(loader_detect_chip(&s_target, &s_reg));
  73. #ifdef SERIAL_FLASHER_INTERFACE_UART
  74. esp_loader_error_t err;
  75. uint32_t spi_config;
  76. if (s_target == ESP8266_CHIP) {
  77. err = loader_flash_begin_cmd(0, 0, 0, 0, s_target);
  78. } else {
  79. RETURN_ON_ERROR( loader_read_spi_config(s_target, &spi_config) );
  80. loader_port_start_timer(DEFAULT_TIMEOUT);
  81. err = loader_spi_attach_cmd(spi_config);
  82. }
  83. return err;
  84. #endif /* SERIAL_FLASHER_INTERFACE_UART */
  85. return ESP_LOADER_SUCCESS;
  86. }
  87. target_chip_t esp_loader_get_target(void)
  88. {
  89. return s_target;
  90. }
  91. #ifdef SERIAL_FLASHER_INTERFACE_UART
  92. static uint32_t s_flash_write_size = 0;
  93. static esp_loader_error_t spi_set_data_lengths(size_t mosi_bits, size_t miso_bits)
  94. {
  95. if (mosi_bits > 0) {
  96. RETURN_ON_ERROR( esp_loader_write_register(s_reg->mosi_dlen, mosi_bits - 1) );
  97. }
  98. if (miso_bits > 0) {
  99. RETURN_ON_ERROR( esp_loader_write_register(s_reg->miso_dlen, miso_bits - 1) );
  100. }
  101. return ESP_LOADER_SUCCESS;
  102. }
  103. static esp_loader_error_t spi_set_data_lengths_8266(size_t mosi_bits, size_t miso_bits)
  104. {
  105. uint32_t mosi_mask = (mosi_bits == 0) ? 0 : mosi_bits - 1;
  106. uint32_t miso_mask = (miso_bits == 0) ? 0 : miso_bits - 1;
  107. return esp_loader_write_register(s_reg->usr1, (miso_mask << 8) | (mosi_mask << 17));
  108. }
  109. static esp_loader_error_t spi_flash_command(spi_flash_cmd_t cmd, void *data_tx, size_t tx_size, void *data_rx, size_t rx_size)
  110. {
  111. assert(rx_size <= 32); // Reading more than 32 bits back from a SPI flash operation is unsupported
  112. assert(tx_size <= 64); // Writing more than 64 bytes of data with one SPI command is unsupported
  113. uint32_t SPI_USR_CMD = (1 << 31);
  114. uint32_t SPI_USR_MISO = (1 << 28);
  115. uint32_t SPI_USR_MOSI = (1 << 27);
  116. uint32_t SPI_CMD_USR = (1 << 18);
  117. uint32_t CMD_LEN_SHIFT = 28;
  118. // Save SPI configuration
  119. uint32_t old_spi_usr;
  120. uint32_t old_spi_usr2;
  121. RETURN_ON_ERROR( esp_loader_read_register(s_reg->usr, &old_spi_usr) );
  122. RETURN_ON_ERROR( esp_loader_read_register(s_reg->usr2, &old_spi_usr2) );
  123. if (s_target == ESP8266_CHIP) {
  124. RETURN_ON_ERROR( spi_set_data_lengths_8266(tx_size, rx_size) );
  125. } else {
  126. RETURN_ON_ERROR( spi_set_data_lengths(tx_size, rx_size) );
  127. }
  128. uint32_t usr_reg_2 = (7 << CMD_LEN_SHIFT) | cmd;
  129. uint32_t usr_reg = SPI_USR_CMD;
  130. if (rx_size > 0) {
  131. usr_reg |= SPI_USR_MISO;
  132. }
  133. if (tx_size > 0) {
  134. usr_reg |= SPI_USR_MOSI;
  135. }
  136. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr, usr_reg) );
  137. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr2, usr_reg_2 ) );
  138. if (tx_size == 0) {
  139. // clear data register before we read it
  140. RETURN_ON_ERROR( esp_loader_write_register(s_reg->w0, 0) );
  141. } else {
  142. uint32_t *data = (uint32_t *)data_tx;
  143. uint32_t words_to_write = (tx_size + 31) / (8 * 4);
  144. uint32_t data_reg_addr = s_reg->w0;
  145. while (words_to_write--) {
  146. uint32_t word = *data++;
  147. RETURN_ON_ERROR( esp_loader_write_register(data_reg_addr, word) );
  148. data_reg_addr += 4;
  149. }
  150. }
  151. RETURN_ON_ERROR( esp_loader_write_register(s_reg->cmd, SPI_CMD_USR) );
  152. uint32_t trials = 10;
  153. while (trials--) {
  154. uint32_t cmd_reg;
  155. RETURN_ON_ERROR( esp_loader_read_register(s_reg->cmd, &cmd_reg) );
  156. if ((cmd_reg & SPI_CMD_USR) == 0) {
  157. break;
  158. }
  159. }
  160. if (trials == 0) {
  161. return ESP_LOADER_ERROR_TIMEOUT;
  162. }
  163. RETURN_ON_ERROR( esp_loader_read_register(s_reg->w0, data_rx) );
  164. // Restore SPI configuration
  165. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr, old_spi_usr) );
  166. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr2, old_spi_usr2) );
  167. return ESP_LOADER_SUCCESS;
  168. }
  169. static esp_loader_error_t detect_flash_size(size_t *flash_size)
  170. {
  171. uint32_t flash_id = 0;
  172. RETURN_ON_ERROR( spi_flash_command(SPI_FLASH_READ_ID, NULL, 0, &flash_id, 24) );
  173. uint32_t size_id = flash_id >> 16;
  174. if (size_id < 0x12 || size_id > 0x18) {
  175. return ESP_LOADER_ERROR_UNSUPPORTED_CHIP;
  176. }
  177. *flash_size = 1 << size_id;
  178. return ESP_LOADER_SUCCESS;
  179. }
  180. static uint32_t calc_erase_size(const target_chip_t target, const uint32_t offset,
  181. const uint32_t image_size)
  182. {
  183. if (target != ESP8266_CHIP) {
  184. return image_size;
  185. } else {
  186. /* Needed to fix a bug in the ESP8266 ROM */
  187. const uint32_t sectors_per_block = 16U;
  188. const uint32_t sector_size = 4096U;
  189. const uint32_t num_sectors = (image_size + sector_size - 1) / sector_size;
  190. const uint32_t start_sector = offset / sector_size;
  191. uint32_t head_sectors = sectors_per_block - (start_sector % sectors_per_block);
  192. /* The ROM bug deletes extra num_sectors if we don't cross the block boundary
  193. and extra head_sectors if we do */
  194. if (num_sectors <= head_sectors) {
  195. return ((num_sectors + 1) / 2) * sector_size;
  196. } else {
  197. return (num_sectors - head_sectors) * sector_size;
  198. }
  199. }
  200. }
  201. esp_loader_error_t esp_loader_flash_start(uint32_t offset, uint32_t image_size, uint32_t block_size)
  202. {
  203. s_flash_write_size = block_size;
  204. size_t flash_size = 0;
  205. if (detect_flash_size(&flash_size) == ESP_LOADER_SUCCESS) {
  206. if (image_size > flash_size) {
  207. return ESP_LOADER_ERROR_IMAGE_SIZE;
  208. }
  209. loader_port_start_timer(DEFAULT_TIMEOUT);
  210. RETURN_ON_ERROR( loader_spi_parameters(flash_size) );
  211. } else {
  212. loader_port_debug_print("Flash size detection failed, falling back to default");
  213. }
  214. init_md5(offset, image_size);
  215. bool encryption_in_cmd = encryption_in_begin_flash_cmd(s_target);
  216. const uint32_t erase_size = calc_erase_size(esp_loader_get_target(), offset, image_size);
  217. const uint32_t blocks_to_write = (image_size + block_size - 1) / block_size;
  218. const uint32_t erase_region_timeout_per_mb = 10000;
  219. loader_port_start_timer(timeout_per_mb(erase_size, erase_region_timeout_per_mb));
  220. return loader_flash_begin_cmd(offset, erase_size, block_size, blocks_to_write, encryption_in_cmd);
  221. }
  222. esp_loader_error_t esp_loader_flash_write(void *payload, uint32_t size)
  223. {
  224. uint32_t padding_bytes = s_flash_write_size - size;
  225. uint8_t *data = (uint8_t *)payload;
  226. uint32_t padding_index = size;
  227. if (size > s_flash_write_size) {
  228. return ESP_LOADER_ERROR_INVALID_PARAM;
  229. }
  230. const uint8_t padding_pattern = 0xFF;
  231. while (padding_bytes--) {
  232. data[padding_index++] = padding_pattern;
  233. }
  234. md5_update(payload, (size + 3) & ~3);
  235. loader_port_start_timer(DEFAULT_TIMEOUT);
  236. return loader_flash_data_cmd(data, s_flash_write_size);
  237. }
  238. esp_loader_error_t esp_loader_flash_finish(bool reboot)
  239. {
  240. loader_port_start_timer(DEFAULT_TIMEOUT);
  241. return loader_flash_end_cmd(!reboot);
  242. }
  243. #endif /* SERIAL_FLASHER_INTERFACE_UART */
  244. esp_loader_error_t esp_loader_mem_start(uint32_t offset, uint32_t size, uint32_t block_size)
  245. {
  246. uint32_t blocks_to_write = ROUNDUP(size, block_size);
  247. loader_port_start_timer(timeout_per_mb(size, LOAD_RAM_TIMEOUT_PER_MB));
  248. return loader_mem_begin_cmd(offset, size, blocks_to_write, block_size);
  249. }
  250. esp_loader_error_t esp_loader_mem_write(const void *payload, uint32_t size)
  251. {
  252. const uint8_t *data = (const uint8_t *)payload;
  253. loader_port_start_timer(timeout_per_mb(size, LOAD_RAM_TIMEOUT_PER_MB));
  254. return loader_mem_data_cmd(data, size);
  255. }
  256. esp_loader_error_t esp_loader_mem_finish(uint32_t entrypoint)
  257. {
  258. loader_port_start_timer(DEFAULT_TIMEOUT);
  259. return loader_mem_end_cmd(entrypoint);
  260. }
  261. esp_loader_error_t esp_loader_read_register(uint32_t address, uint32_t *reg_value)
  262. {
  263. loader_port_start_timer(DEFAULT_TIMEOUT);
  264. return loader_read_reg_cmd(address, reg_value);
  265. }
  266. esp_loader_error_t esp_loader_write_register(uint32_t address, uint32_t reg_value)
  267. {
  268. loader_port_start_timer(DEFAULT_TIMEOUT);
  269. return loader_write_reg_cmd(address, reg_value, 0xFFFFFFFF, 0);
  270. }
  271. esp_loader_error_t esp_loader_change_transmission_rate(uint32_t transmission_rate)
  272. {
  273. if (s_target == ESP8266_CHIP) {
  274. return ESP_LOADER_ERROR_UNSUPPORTED_FUNC;
  275. }
  276. loader_port_start_timer(DEFAULT_TIMEOUT);
  277. return loader_change_baudrate_cmd(transmission_rate);
  278. }
  279. #if MD5_ENABLED
  280. static void hexify(const uint8_t raw_md5[16], uint8_t hex_md5_out[32])
  281. {
  282. static const uint8_t dec_to_hex[] = {
  283. '0', '1', '2', '3', '4', '5', '6', '7',
  284. '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'
  285. };
  286. for (int i = 0; i < 16; i++) {
  287. *hex_md5_out++ = dec_to_hex[raw_md5[i] >> 4];
  288. *hex_md5_out++ = dec_to_hex[raw_md5[i] & 0xF];
  289. }
  290. }
  291. esp_loader_error_t esp_loader_flash_verify(void)
  292. {
  293. if (s_target == ESP8266_CHIP) {
  294. return ESP_LOADER_ERROR_UNSUPPORTED_FUNC;
  295. }
  296. uint8_t raw_md5[16] = {0};
  297. /* Zero termination and new line character require 2 bytes */
  298. uint8_t hex_md5[MD5_SIZE + 2] = {0};
  299. uint8_t received_md5[MD5_SIZE + 2] = {0};
  300. md5_final(raw_md5);
  301. hexify(raw_md5, hex_md5);
  302. loader_port_start_timer(timeout_per_mb(s_image_size, MD5_TIMEOUT_PER_MB));
  303. RETURN_ON_ERROR( loader_md5_cmd(s_start_address, s_image_size, received_md5) );
  304. bool md5_match = memcmp(hex_md5, received_md5, MD5_SIZE) == 0;
  305. if (!md5_match) {
  306. hex_md5[MD5_SIZE] = '\n';
  307. received_md5[MD5_SIZE] = '\n';
  308. loader_port_debug_print("Error: MD5 checksum does not match:\n");
  309. loader_port_debug_print("Expected:\n");
  310. loader_port_debug_print((char *)received_md5);
  311. loader_port_debug_print("Actual:\n");
  312. loader_port_debug_print((char *)hex_md5);
  313. return ESP_LOADER_ERROR_INVALID_MD5;
  314. }
  315. return ESP_LOADER_SUCCESS;
  316. }
  317. #endif
  318. void esp_loader_reset_target(void)
  319. {
  320. loader_port_reset_target();
  321. }