esp_loader.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364
  1. /* Copyright 2020 Espressif Systems (Shanghai) PTE LTD
  2. *
  3. * Licensed under the Apache License, Version 2.0 (the "License");
  4. * you may not use this file except in compliance with the License.
  5. * You may obtain a copy of the License at
  6. *
  7. * http://www.apache.org/licenses/LICENSE-2.0
  8. *
  9. * Unless required by applicable law or agreed to in writing, software
  10. * distributed under the License is distributed on an "AS IS" BASIS,
  11. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. * See the License for the specific language governing permissions and
  13. * limitations under the License.
  14. */
  15. #include "serial_comm_prv.h"
  16. #include "serial_comm.h"
  17. #include "serial_io.h"
  18. #include "esp_loader.h"
  19. #include "esp_targets.h"
  20. #include "md5_hash.h"
  21. #include <string.h>
  22. #include <assert.h>
  23. #ifndef MAX
  24. #define MAX(a, b) ((a) > (b)) ? (a) : (b)
  25. #endif
  26. #ifndef MIN
  27. #define MIN(a, b) ((a) < (b)) ? (a) : (b)
  28. #endif
  29. static const uint32_t DEFAULT_TIMEOUT = 1000;
  30. static const uint32_t DEFAULT_FLASH_TIMEOUT = 3000; // timeout for most flash operations
  31. static const uint32_t ERASE_REGION_TIMEOUT_PER_MB = 10000; // timeout (per megabyte) for erasing a region
  32. static const uint8_t PADDING_PATTERN = 0xFF;
  33. typedef enum {
  34. SPI_FLASH_READ_ID = 0x9F
  35. } spi_flash_cmd_t;
  36. static uint32_t s_flash_write_size = 0;
  37. static const target_registers_t *s_reg = NULL;
  38. static target_chip_t s_target = ESP_UNKNOWN_CHIP;
  39. #if MD5_ENABLED
  40. static const uint32_t MD5_TIMEOUT_PER_MB = 800;
  41. static struct MD5Context s_md5_context;
  42. static uint32_t s_start_address;
  43. static uint32_t s_image_size;
  44. static inline void init_md5(uint32_t address, uint32_t size)
  45. {
  46. s_start_address = address;
  47. s_image_size = size;
  48. MD5Init(&s_md5_context);
  49. }
  50. static inline void md5_update(const uint8_t *data, uint32_t size)
  51. {
  52. MD5Update(&s_md5_context, data, size);
  53. }
  54. static inline void md5_final(uint8_t digets[16])
  55. {
  56. MD5Final(digets, &s_md5_context);
  57. }
  58. #else
  59. static inline void init_md5(uint32_t address, uint32_t size) { }
  60. static inline void md5_update(const uint8_t *data, uint32_t size) { }
  61. static inline void md5_final(uint8_t digets[16]) { }
  62. #endif
  63. static uint32_t timeout_per_mb(uint32_t size_bytes, uint32_t time_per_mb)
  64. {
  65. uint32_t timeout = time_per_mb * (size_bytes / 1e6);
  66. return MAX(timeout, DEFAULT_FLASH_TIMEOUT);
  67. }
  68. esp_loader_error_t esp_loader_connect(esp_loader_connect_args_t *connect_args)
  69. {
  70. uint32_t spi_config;
  71. esp_loader_error_t err;
  72. int32_t trials = connect_args->trials;
  73. loader_port_enter_bootloader();
  74. do {
  75. loader_port_start_timer(connect_args->sync_timeout);
  76. err = loader_sync_cmd();
  77. if (err == ESP_LOADER_ERROR_TIMEOUT) {
  78. if (--trials == 0) {
  79. return ESP_LOADER_ERROR_TIMEOUT;
  80. }
  81. loader_port_delay_ms(100);
  82. } else if (err != ESP_LOADER_SUCCESS) {
  83. return err;
  84. }
  85. } while (err != ESP_LOADER_SUCCESS);
  86. RETURN_ON_ERROR( loader_detect_chip(&s_target, &s_reg) );
  87. if (s_target == ESP8266_CHIP) {
  88. err = loader_flash_begin_cmd(0, 0, 0, 0, s_target);
  89. } else {
  90. RETURN_ON_ERROR( loader_read_spi_config(s_target, &spi_config) );
  91. loader_port_start_timer(DEFAULT_TIMEOUT);
  92. err = loader_spi_attach_cmd(spi_config);
  93. }
  94. return err;
  95. }
  96. target_chip_t esp_loader_get_target(void)
  97. {
  98. return s_target;
  99. }
  100. static esp_loader_error_t spi_set_data_lengths(size_t mosi_bits, size_t miso_bits)
  101. {
  102. if (mosi_bits > 0) {
  103. RETURN_ON_ERROR( esp_loader_write_register(s_reg->mosi_dlen, mosi_bits - 1) );
  104. }
  105. if (miso_bits > 0) {
  106. RETURN_ON_ERROR( esp_loader_write_register(s_reg->miso_dlen, miso_bits - 1) );
  107. }
  108. return ESP_LOADER_SUCCESS;
  109. }
  110. static esp_loader_error_t spi_set_data_lengths_8266(size_t mosi_bits, size_t miso_bits)
  111. {
  112. uint32_t mosi_mask = (mosi_bits == 0) ? 0 : mosi_bits - 1;
  113. uint32_t miso_mask = (miso_bits == 0) ? 0 : miso_bits - 1;
  114. return esp_loader_write_register(s_reg->usr1, (miso_mask << 8) | (mosi_mask << 17));
  115. }
  116. static esp_loader_error_t spi_flash_command(spi_flash_cmd_t cmd, void *data_tx, size_t tx_size, void *data_rx, size_t rx_size)
  117. {
  118. assert(rx_size <= 32); // Reading more than 32 bits back from a SPI flash operation is unsupported
  119. assert(tx_size <= 64); // Writing more than 64 bytes of data with one SPI command is unsupported
  120. uint32_t SPI_USR_CMD = (1 << 31);
  121. uint32_t SPI_USR_MISO = (1 << 28);
  122. uint32_t SPI_USR_MOSI = (1 << 27);
  123. uint32_t SPI_CMD_USR = (1 << 18);
  124. uint32_t CMD_LEN_SHIFT = 28;
  125. // Save SPI configuration
  126. uint32_t old_spi_usr;
  127. uint32_t old_spi_usr2;
  128. RETURN_ON_ERROR( esp_loader_read_register(s_reg->usr, &old_spi_usr) );
  129. RETURN_ON_ERROR( esp_loader_read_register(s_reg->usr2, &old_spi_usr2) );
  130. if (s_target == ESP8266_CHIP) {
  131. RETURN_ON_ERROR( spi_set_data_lengths_8266(tx_size, rx_size) );
  132. } else {
  133. RETURN_ON_ERROR( spi_set_data_lengths(tx_size, rx_size) );
  134. }
  135. uint32_t usr_reg_2 = (7 << CMD_LEN_SHIFT) | cmd;
  136. uint32_t usr_reg = SPI_USR_CMD;
  137. if (rx_size > 0) {
  138. usr_reg |= SPI_USR_MISO;
  139. }
  140. if (tx_size > 0) {
  141. usr_reg |= SPI_USR_MOSI;
  142. }
  143. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr, usr_reg) );
  144. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr2, usr_reg_2 ) );
  145. if (tx_size == 0) {
  146. // clear data register before we read it
  147. RETURN_ON_ERROR( esp_loader_write_register(s_reg->w0, 0) );
  148. } else {
  149. uint32_t *data = (uint32_t *)data_tx;
  150. uint32_t words_to_write = (tx_size + 31) / (8 * 4);
  151. uint32_t data_reg_addr = s_reg->w0;
  152. while (words_to_write--) {
  153. uint32_t word = *data++;
  154. RETURN_ON_ERROR( esp_loader_write_register(data_reg_addr, word) );
  155. data_reg_addr += 4;
  156. }
  157. }
  158. RETURN_ON_ERROR( esp_loader_write_register(s_reg->cmd, SPI_CMD_USR) );
  159. uint32_t trials = 10;
  160. while (trials--) {
  161. uint32_t cmd_reg;
  162. RETURN_ON_ERROR( esp_loader_read_register(s_reg->cmd, &cmd_reg) );
  163. if ((cmd_reg & SPI_CMD_USR) == 0) {
  164. break;
  165. }
  166. }
  167. if (trials == 0) {
  168. return ESP_LOADER_ERROR_TIMEOUT;
  169. }
  170. RETURN_ON_ERROR( esp_loader_read_register(s_reg->w0, data_rx) );
  171. // Restore SPI configuration
  172. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr, old_spi_usr) );
  173. RETURN_ON_ERROR( esp_loader_write_register(s_reg->usr2, old_spi_usr2) );
  174. return ESP_LOADER_SUCCESS;
  175. }
  176. static esp_loader_error_t detect_flash_size(size_t *flash_size)
  177. {
  178. uint32_t flash_id = 0;
  179. RETURN_ON_ERROR( spi_flash_command(SPI_FLASH_READ_ID, NULL, 0, &flash_id, 24) );
  180. uint32_t size_id = flash_id >> 16;
  181. if (size_id < 0x12 || size_id > 0x18) {
  182. return ESP_LOADER_ERROR_UNSUPPORTED_CHIP;
  183. }
  184. *flash_size = 1 << size_id;
  185. return ESP_LOADER_SUCCESS;
  186. }
  187. esp_loader_error_t esp_loader_flash_start(uint32_t offset, uint32_t image_size, uint32_t block_size)
  188. {
  189. uint32_t blocks_to_write = (image_size + block_size - 1) / block_size;
  190. uint32_t erase_size = block_size * blocks_to_write;
  191. s_flash_write_size = block_size;
  192. size_t flash_size = 0;
  193. if (detect_flash_size(&flash_size) == ESP_LOADER_SUCCESS) {
  194. if (image_size > flash_size) {
  195. return ESP_LOADER_ERROR_IMAGE_SIZE;
  196. }
  197. loader_port_start_timer(DEFAULT_TIMEOUT);
  198. RETURN_ON_ERROR( loader_spi_parameters(flash_size) );
  199. } else {
  200. loader_port_debug_print("Flash size detection failed, falling back to default");
  201. }
  202. init_md5(offset, image_size);
  203. loader_port_start_timer(timeout_per_mb(erase_size, ERASE_REGION_TIMEOUT_PER_MB));
  204. return loader_flash_begin_cmd(offset, erase_size, block_size, blocks_to_write, s_target);
  205. }
  206. esp_loader_error_t esp_loader_flash_write(void *payload, uint32_t size)
  207. {
  208. uint32_t padding_bytes = s_flash_write_size - size;
  209. uint8_t *data = (uint8_t *)payload;
  210. uint32_t padding_index = size;
  211. while (padding_bytes--) {
  212. data[padding_index++] = PADDING_PATTERN;
  213. }
  214. md5_update(payload, (size + 3) & ~3);
  215. loader_port_start_timer(DEFAULT_TIMEOUT);
  216. return loader_flash_data_cmd(data, s_flash_write_size);
  217. }
  218. esp_loader_error_t esp_loader_flash_finish(bool reboot)
  219. {
  220. loader_port_start_timer(DEFAULT_TIMEOUT);
  221. return loader_flash_end_cmd(!reboot);
  222. }
  223. esp_loader_error_t esp_loader_read_register(uint32_t address, uint32_t *reg_value)
  224. {
  225. loader_port_start_timer(DEFAULT_TIMEOUT);
  226. return loader_read_reg_cmd(address, reg_value);
  227. }
  228. esp_loader_error_t esp_loader_write_register(uint32_t address, uint32_t reg_value)
  229. {
  230. loader_port_start_timer(DEFAULT_TIMEOUT);
  231. return loader_write_reg_cmd(address, reg_value, 0xFFFFFFFF, 0);
  232. }
  233. esp_loader_error_t esp_loader_change_baudrate(uint32_t baudrate)
  234. {
  235. if (s_target == ESP8266_CHIP) {
  236. return ESP_LOADER_ERROR_UNSUPPORTED_FUNC;
  237. }
  238. loader_port_start_timer(DEFAULT_TIMEOUT);
  239. return loader_change_baudrate_cmd(baudrate);
  240. }
  241. #if MD5_ENABLED
  242. static void hexify(const uint8_t raw_md5[16], uint8_t hex_md5_out[32])
  243. {
  244. static const uint8_t dec_to_hex[] = {
  245. '0', '1', '2', '3', '4', '5', '6', '7',
  246. '8', '9', 'a', 'b', 'c', 'd', 'e', 'f'
  247. };
  248. for (int i = 0; i < 16; i++) {
  249. *hex_md5_out++ = dec_to_hex[raw_md5[i] >> 4];
  250. *hex_md5_out++ = dec_to_hex[raw_md5[i] & 0xF];
  251. }
  252. }
  253. esp_loader_error_t esp_loader_flash_verify(void)
  254. {
  255. if (s_target == ESP8266_CHIP) {
  256. return ESP_LOADER_ERROR_UNSUPPORTED_FUNC;
  257. }
  258. uint8_t raw_md5[16];
  259. uint8_t hex_md5[MD5_SIZE + 1];
  260. uint8_t received_md5[MD5_SIZE + 1];
  261. md5_final(raw_md5);
  262. hexify(raw_md5, hex_md5);
  263. loader_port_start_timer(timeout_per_mb(s_image_size, MD5_TIMEOUT_PER_MB));
  264. RETURN_ON_ERROR( loader_md5_cmd(s_start_address, s_image_size, received_md5) );
  265. bool md5_match = memcmp(hex_md5, received_md5, MD5_SIZE) == 0;
  266. if (!md5_match) {
  267. hex_md5[MD5_SIZE] = '\n';
  268. received_md5[MD5_SIZE] = '\n';
  269. loader_port_debug_print("Error: MD5 checksum does not match:\n");
  270. loader_port_debug_print("Expected:\n");
  271. loader_port_debug_print((char *)received_md5);
  272. loader_port_debug_print("Actual:\n");
  273. loader_port_debug_print((char *)hex_md5);
  274. return ESP_LOADER_ERROR_INVALID_MD5;
  275. }
  276. return ESP_LOADER_SUCCESS;
  277. }
  278. #endif
  279. void esp_loader_reset_target(void)
  280. {
  281. loader_port_reset_target();
  282. }