Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2015 Google Inc. |
| 3 | * |
| 4 | * This program is free software; you can redistribute it and/or modify |
| 5 | * it under the terms of the GNU General Public License as published by |
| 6 | * the Free Software Foundation; version 2 of the License. |
| 7 | * |
| 8 | * This program is distributed in the hope that it will be useful, |
| 9 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 10 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
| 11 | * GNU General Public License for more details. |
| 12 | * |
| 13 | * You should have received a copy of the GNU General Public License |
| 14 | * along with this program; if not, write to the Free Software |
Martin Roth | b54d6ba | 2015-09-29 14:49:37 -0600 | [diff] [blame] | 15 | * Foundation, Inc. |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 16 | */ |
| 17 | |
| 18 | #include <stdio.h> |
| 19 | #include <stdlib.h> |
| 20 | #include <string.h> |
| 21 | |
| 22 | #include "em100.h" |
| 23 | |
| 24 | /* file format: |
| 25 | * |
| 26 | * 0x0000000: 65 6d 31 30 30 70 72 6f - magic 8 bytes |
| 27 | * 0x0000014: 32 2e 32 36 - version MCU |
| 28 | * 0x000001e: 30 2e 37 35 - version FPGA |
| 29 | * 0x0000028: 57 46 50 44 - WFPD (??) |
| 30 | * 0x0000038: 00 01 00 00 - file offset FPGA |
| 31 | * 0x000003c: 44 15 07 00 - file length FPGA |
| 32 | * 0x0000040: 00 17 07 00 - file offset MCU |
| 33 | * 0x0000044: 00 bf 00 00 - file length MCU |
| 34 | * |
| 35 | * flash layout |
| 36 | * 0x0000000: fpga firmware |
| 37 | * 0x0100000: 256 bytes of 0x00 filled space |
| 38 | * 0x0100100: mcu firmware |
| 39 | * 0x01f0000: 4 bytes secret key, 00 padded |
| 40 | * 0x01fff00: ff ff 4 bytes serial number ff padded |
| 41 | * |
| 42 | * - empty pages remain 0xff filled |
| 43 | * - partially used pages are typically filled up with 00 bytes |
| 44 | * except the page containing the serial number |
| 45 | */ |
| 46 | |
| 47 | #undef DEBUG |
| 48 | |
| 49 | static void print_progress(int percent) |
| 50 | { |
| 51 | int i; |
| 52 | |
| 53 | putchar('\r'); |
| 54 | putchar('['); |
| 55 | for (i = 0; i < percent / 2; i++) |
| 56 | putchar('='); |
| 57 | for (i = 0; i < 50 - (percent / 2); i++) |
| 58 | putchar(' '); |
| 59 | putchar(']'); |
| 60 | if (percent == 100) |
| 61 | putchar('\n'); |
| 62 | fflush(stdout); |
| 63 | } |
| 64 | |
| 65 | static uint32_t get_le32(const unsigned char *in) |
| 66 | { |
| 67 | return (in[3] << 24) | (in[2] << 16) | (in[1] << 8) | (in[0] << 0); |
| 68 | } |
| 69 | |
Stefan Reinauer | a9278a9 | 2015-09-01 16:16:27 -0700 | [diff] [blame] | 70 | static void put_le32(unsigned char *out, uint32_t val) |
| 71 | { |
| 72 | out[0] = val&0xff; |
| 73 | out[1] = (val>>8)&0xff; |
| 74 | out[2] = (val>>16)&0xff; |
| 75 | out[3] = (val>>24)&0xff; |
| 76 | } |
| 77 | |
Martin Roth | b54d6ba | 2015-09-29 14:49:37 -0600 | [diff] [blame] | 78 | int firmware_dump(struct em100 *em100, const char *filename, |
| 79 | int firmware_is_dpfw) |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 80 | { |
| 81 | #define ROM_SIZE (2*1024*1024) |
| 82 | unsigned char data[ROM_SIZE]; |
| 83 | int i; |
| 84 | FILE *fw; |
| 85 | |
| 86 | printf("\nWriting EM100Pro firmware to file %s\n", filename); |
| 87 | memset(data, 0, ROM_SIZE); |
| 88 | for (i=0; i < ROM_SIZE; i+=256) { |
| 89 | if((i & 0x7fff) == 0) |
| 90 | print_progress(i * 100 / ROM_SIZE); |
| 91 | if (!read_spi_flash_page(em100, i, data+i)) { |
| 92 | if (!read_spi_flash_page(em100, i, data+i)) |
| 93 | if (!read_spi_flash_page(em100, i, data+i)) |
Martin Roth | b54d6ba | 2015-09-29 14:49:37 -0600 | [diff] [blame] | 94 | printf("\nERROR: Couldn't read @%08x\n", |
| 95 | i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 96 | } |
| 97 | } |
| 98 | print_progress(100); |
| 99 | fw = fopen(filename, "wb"); |
Stefan Reinauer | a9278a9 | 2015-09-01 16:16:27 -0700 | [diff] [blame] | 100 | if (!fw) { |
| 101 | perror(filename); |
| 102 | return 0; |
| 103 | } |
| 104 | |
| 105 | if (firmware_is_dpfw) { |
| 106 | int fpga_size = 0, mcu_size = 0; |
| 107 | char *all_ff[256]; |
| 108 | char mcu_version[8]; |
| 109 | char fpga_version[8]; |
| 110 | unsigned char header[0x100]; |
| 111 | |
| 112 | memset(all_ff, 255, 256); |
| 113 | for (i = 0; i < 0x100000; i+=0x100) { |
| 114 | if (memcmp(data+i, all_ff, 256) == 0) |
| 115 | break; |
| 116 | } |
| 117 | if (i == 0x100000) { |
| 118 | printf("Can't parse device firmware. Please extract" |
| 119 | " raw firmware instead.\n"); |
| 120 | exit(1); |
| 121 | } |
| 122 | fpga_size = i; |
| 123 | |
| 124 | for (i = 0; i < 0xfff00; i+=0x100) { |
| 125 | if (memcmp(data+0x100100+i, all_ff, 256) == 0) |
| 126 | break; |
| 127 | } |
| 128 | if (i == 0xfff00) { |
| 129 | printf("Can't parse device firmware. Please extract" |
| 130 | " raw firmware instead.\n"); |
| 131 | exit(1); |
| 132 | } |
| 133 | mcu_size = i; |
| 134 | |
| 135 | snprintf(mcu_version, 8, "%d.%d", |
| 136 | em100->mcu >> 8, em100->mcu & 0xff); |
| 137 | snprintf(fpga_version, 8, "%d.%d", |
| 138 | em100->fpga >> 8 & 0x7f, em100->fpga & 0xff); |
| 139 | |
| 140 | memset(header, 0, 0x100); |
| 141 | memcpy(header, "em100pro", 8); |
| 142 | memcpy(header + 0x28, "WFPD", 4); |
| 143 | memcpy(header + 0x14, mcu_version, 4); |
| 144 | memcpy(header + 0x1e, fpga_version, 4); |
| 145 | put_le32(header + 0x38, 0x100); |
| 146 | put_le32(header + 0x3c, fpga_size); |
| 147 | put_le32(header + 0x40, 0x100 + fpga_size); |
| 148 | put_le32(header + 0x44, 0x100 + mcu_size); |
| 149 | fwrite(header, 0x100, 1, fw); |
| 150 | fwrite(data, fpga_size, 1, fw); |
| 151 | fwrite(data + 0x100100, mcu_size, 1, fw); |
| 152 | } else { |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 153 | if (fwrite(data, ROM_SIZE, 1, fw) != 1) |
| 154 | printf("ERROR: Couldn't write %s\n", filename); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 155 | } |
Stefan Reinauer | a9278a9 | 2015-09-01 16:16:27 -0700 | [diff] [blame] | 156 | fclose(fw); |
| 157 | |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 158 | #if DEBUG |
| 159 | hexdump(data, ROM_SIZE); |
| 160 | #endif |
| 161 | return 0; |
| 162 | } |
| 163 | |
| 164 | int firmware_update(struct em100 *em100, const char *filename, int verify) |
| 165 | { |
Stefan Reinauer | b825c92 | 2015-10-10 09:05:58 +0000 | [diff] [blame] | 166 | #define MAX_VERSION_LENGTH 10 |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 167 | unsigned char page[256], vpage[256]; |
| 168 | FILE *f; |
| 169 | long fsize; |
| 170 | unsigned char *fw; |
| 171 | int i; |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 172 | int fpga_offset, fpga_len, mcu_offset, mcu_len; |
Stefan Reinauer | b825c92 | 2015-10-10 09:05:58 +0000 | [diff] [blame] | 173 | char fpga_version[MAX_VERSION_LENGTH + 1], |
| 174 | mcu_version[MAX_VERSION_LENGTH + 1]; |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 175 | |
| 176 | printf("\nAttempting firmware update with file %s\n", filename); |
| 177 | |
| 178 | f = fopen(filename, "rb"); |
| 179 | if (!f) { |
| 180 | perror(filename); |
| 181 | return 0; |
| 182 | } |
| 183 | |
| 184 | fseek(f, 0, SEEK_END); |
| 185 | fsize = ftell(f); |
Stefan Reinauer | 85c22ea | 2015-10-09 13:53:56 +0000 | [diff] [blame] | 186 | if (fsize < 0) { |
| 187 | perror(filename); |
| 188 | return 0; |
| 189 | } |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 190 | fseek(f, 0, SEEK_SET); |
| 191 | |
| 192 | fw = malloc(fsize); |
| 193 | if (fread(fw, fsize, 1, f) != 1) { |
| 194 | perror(filename); |
| 195 | fclose(f); |
Stefan Reinauer | b02440f | 2015-10-10 08:45:30 +0000 | [diff] [blame] | 196 | free(fw); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 197 | return 0; |
| 198 | } |
| 199 | fclose(f); |
| 200 | |
| 201 | if (memcmp(fw, "em100pro", 8) != 0 || |
| 202 | memcmp(fw + 0x28, "WFPD", 4) != 0) { |
| 203 | printf("ERROR: Not an EM100Pro firmware file.\n"); |
| 204 | free(fw); |
| 205 | return 0; |
| 206 | } |
| 207 | |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 208 | /* Find firmwares in the update file */ |
| 209 | fpga_offset = get_le32(fw+0x38); |
| 210 | fpga_len = get_le32(fw+0x3c); |
| 211 | mcu_offset = get_le32(fw+0x40); |
| 212 | mcu_len = get_le32(fw+0x44); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 213 | |
Stefan Reinauer | b825c92 | 2015-10-10 09:05:58 +0000 | [diff] [blame] | 214 | /* Extracting versions */ |
| 215 | strncpy(mcu_version, (char *)fw + 0x14, MAX_VERSION_LENGTH); |
| 216 | mcu_version[MAX_VERSION_LENGTH] = '\0'; |
| 217 | strncpy(fpga_version, (char *)fw + 0x1e, MAX_VERSION_LENGTH); |
| 218 | fpga_version[MAX_VERSION_LENGTH] = '\0'; |
| 219 | |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 220 | printf("EM100Pro Update File: %s\n", filename); |
| 221 | printf(" Installed version: MCU %d.%d, FPGA %d.%d (%s)\n", |
| 222 | em100->mcu >> 8, em100->mcu & 0xff, |
| 223 | em100->fpga >> 8 & 0x7f, em100->fpga & 0xff, |
| 224 | em100->fpga & 0x8000 ? "1.8V" : "3.3V"); |
Stefan Reinauer | b825c92 | 2015-10-10 09:05:58 +0000 | [diff] [blame] | 225 | printf(" New version: MCU %s, FPGA %s\n", |
| 226 | mcu_version, fpga_version); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 227 | |
Stefan Reinauer | 2d83616 | 2015-10-10 09:40:07 +0000 | [diff] [blame^] | 228 | if (fpga_len < 256 || mcu_len < 256) { |
| 229 | printf("\nFirmware file not valid.\n"); |
| 230 | free(fw); |
| 231 | return 0; |
| 232 | } |
| 233 | |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 234 | /* Unlock and erase sector. Reading |
| 235 | * the SPI flash ID is requires to |
| 236 | * actually unlock the chip. |
| 237 | */ |
| 238 | unlock_spi_flash(em100); |
| 239 | get_spi_flash_id(em100); |
| 240 | |
| 241 | printf("Erasing firmware:\n"); |
| 242 | for (i=0; i<=0x1e; i++) { |
| 243 | print_progress(i * 100 / 0x1e); |
| 244 | erase_spi_flash_sector(em100, i); |
| 245 | } |
| 246 | get_spi_flash_id(em100); // Needed? |
| 247 | |
| 248 | printf("Writing firmware:\n"); |
| 249 | |
| 250 | /* Writing FPGA firmware */ |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 251 | for (i = 0; i < fpga_len; i += 256) { |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 252 | memset(page, 0xff, 256); |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 253 | memcpy(page, fw + fpga_offset + i, fpga_len - i |
| 254 | > 256 ? 256 : fpga_len - i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 255 | write_spi_flash_page(em100, i, page); |
| 256 | if ((i & 0xfff) == 0) |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 257 | print_progress((i * 100) / (fpga_len + mcu_len)); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 258 | } |
| 259 | |
| 260 | /* Writing MCU firmware */ |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 261 | for (i = 0; i < mcu_len; i += 256) { |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 262 | memset(page, 0xff, 256); |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 263 | memcpy(page, fw + mcu_offset + i, mcu_len - i |
| 264 | > 256 ? 256 : mcu_len - i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 265 | write_spi_flash_page(em100, i + 0x100100, page); |
| 266 | if ((i & 0xfff) == 0) |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 267 | print_progress(((fpga_len + i) * 100) / |
| 268 | (fpga_len + mcu_len)); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 269 | } |
| 270 | print_progress(100); |
| 271 | |
| 272 | if (verify) { |
| 273 | printf("Verifying firmware:\n"); |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 274 | for (i = 0; i < fpga_len; i += 256) { |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 275 | memset(page, 0xff, 256); |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 276 | memcpy(page, fw + fpga_offset + i, fpga_len - i |
| 277 | > 256 ? 256 : fpga_len - i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 278 | read_spi_flash_page(em100, i, vpage); |
| 279 | |
| 280 | if ((i & 0xfff) == 0) |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 281 | print_progress((i * 100) / (fpga_len + mcu_len)); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 282 | if (memcmp(page, vpage, 256)) |
Martin Roth | b54d6ba | 2015-09-29 14:49:37 -0600 | [diff] [blame] | 283 | printf("\nERROR: Could not write FPGA firmware" |
| 284 | " (%x).\n", i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 285 | } |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 286 | for (i = 0; i < mcu_len; i += 256) { |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 287 | memset(page, 0xff, 256); |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 288 | memcpy(page, fw + mcu_offset + i, mcu_len - i |
| 289 | > 256 ? 256 : mcu_len - i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 290 | read_spi_flash_page(em100, i + 0x100100, vpage); |
| 291 | |
| 292 | if ((i & 0xfff) == 0) |
Stefan Reinauer | 826d668 | 2015-10-10 08:33:41 +0000 | [diff] [blame] | 293 | print_progress(((fpga_len + i) * 100) / |
| 294 | (fpga_len + mcu_len)); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 295 | if (memcmp(page, vpage, 256)) |
Martin Roth | b54d6ba | 2015-09-29 14:49:37 -0600 | [diff] [blame] | 296 | printf("\nERROR: Could not write MCU firmware" |
| 297 | " (%x).\n", i); |
Stefan Reinauer | a2b67d3 | 2015-09-01 16:30:43 -0700 | [diff] [blame] | 298 | } |
| 299 | } |
| 300 | print_progress(100); |
| 301 | |
| 302 | free(fw); |
| 303 | |
| 304 | /* Write magic update page */ |
| 305 | memset(page, 0x00, 256); |
| 306 | page[0] = 0xaa; |
| 307 | page[1] = 0x55; |
| 308 | page[2] = 0x42; |
| 309 | page[3] = 0x4f; |
| 310 | page[4] = 0x4f; |
| 311 | page[5] = 0x54; |
| 312 | page[6] = 0x55; |
| 313 | page[7] = 0xaa; |
| 314 | write_spi_flash_page(em100, 0x100000, page); |
| 315 | |
| 316 | if (verify) { |
| 317 | read_spi_flash_page(em100, 0x100000, vpage); |
| 318 | if (memcmp(page, vpage, 256)) |
| 319 | printf("ERROR: Could not write update tag.\n"); |
| 320 | } |
| 321 | |
| 322 | printf("\nDisconnect and reconnect your EM100pro\n"); |
| 323 | |
| 324 | return 1; |
| 325 | } |