2 * This file is part of the flashrom project.
4 * Copyright (C) 2000 Silicon Integrated System Corporation
5 * Copyright (C) 2006 Giampiero Giancipoli <gianci@email.it>
6 * Copyright (C) 2006 coresystems GmbH <info@coresystems.de>
7 * Copyright (C) 2007 Carl-Daniel Hailfinger
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License as published by
11 * the Free Software Foundation; either version 2 of the License, or
12 * (at your option) any later version.
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 * GNU General Public License for more details.
19 * You should have received a copy of the GNU General Public License
20 * along with this program; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
28 #define MAX_REFLASH_TRIES 0x10
30 /* Check one byte for odd parity */
31 uint8_t oddparity(uint8_t val)
33 val = (val ^ (val >> 4)) & 0xf;
34 val = (val ^ (val >> 2)) & 0x3;
35 return (val ^ (val >> 1)) & 0x1;
38 void toggle_ready_jedec(volatile uint8_t *dst)
45 while (i++ < 0xFFFFFFF) {
54 void data_polling_jedec(volatile uint8_t *dst, uint8_t data)
61 while (i++ < 0xFFFFFFF) {
69 void unprotect_jedec(volatile uint8_t *bios)
71 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
72 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
73 *(volatile uint8_t *)(bios + 0x5555) = 0x80;
74 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
75 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
76 *(volatile uint8_t *)(bios + 0x5555) = 0x20;
81 void protect_jedec(volatile uint8_t *bios)
83 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
84 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
85 *(volatile uint8_t *)(bios + 0x5555) = 0xA0;
90 int probe_jedec(struct flashchip *flash)
92 volatile uint8_t *bios = flash->virtual_memory;
94 uint32_t largeid1, largeid2;
96 /* Issue JEDEC Product ID Entry command */
97 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
99 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
101 *(volatile uint8_t *)(bios + 0x5555) = 0x90;
102 /* Older chips may need up to 100 us to respond. The ATMEL 29C020
103 * needs 10 ms according to the data sheet, but it has been tested
104 * to work reliably with 2 ms.
108 /* Read product ID */
109 id1 = *(volatile uint8_t *)bios;
110 id2 = *(volatile uint8_t *)(bios + 0x01);
114 /* Check if it is a continuation ID, this should be a while loop. */
117 id1 = *(volatile uint8_t *)(bios + 0x100);
122 id2 = *(volatile uint8_t *)(bios + 0x101);
126 /* Issue JEDEC Product ID Exit command */
127 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
129 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
131 *(volatile uint8_t *)(bios + 0x5555) = 0xF0;
134 printf_debug("%s: id1 0x%x, id2 0x%x", __FUNCTION__, largeid1, largeid2);
136 printf_debug(", id1 parity violation");
138 if (largeid1 == flash->manufacture_id && largeid2 == flash->model_id)
144 int erase_sector_jedec(volatile uint8_t *bios, unsigned int page)
146 /* Issue the Sector Erase command */
147 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
149 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
151 *(volatile uint8_t *)(bios + 0x5555) = 0x80;
154 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
156 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
158 *(volatile uint8_t *)(bios + page) = 0x30;
161 /* wait for Toggle bit ready */
162 toggle_ready_jedec(bios);
167 int erase_block_jedec(volatile uint8_t *bios, unsigned int block)
169 /* Issue the Sector Erase command */
170 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
172 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
174 *(volatile uint8_t *)(bios + 0x5555) = 0x80;
177 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
179 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
181 *(volatile uint8_t *)(bios + block) = 0x50;
184 /* wait for Toggle bit ready */
185 toggle_ready_jedec(bios);
190 int erase_chip_jedec(struct flashchip *flash)
192 volatile uint8_t *bios = flash->virtual_memory;
194 /* Issue the JEDEC Chip Erase command */
195 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
197 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
199 *(volatile uint8_t *)(bios + 0x5555) = 0x80;
202 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
204 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
206 *(volatile uint8_t *)(bios + 0x5555) = 0x10;
209 toggle_ready_jedec(bios);
214 int write_page_write_jedec(volatile uint8_t *bios, uint8_t *src,
215 volatile uint8_t *dst, int page_size)
217 int i, tried = 0, start_index = 0, ok;
218 volatile uint8_t *d = dst;
222 /* Issue JEDEC Data Unprotect comand */
223 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
224 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
225 *(volatile uint8_t *)(bios + 0x5555) = 0xA0;
227 /* transfer data from source to destination */
228 for (i = start_index; i < page_size; i++) {
229 /* If the data is 0xFF, don't program it */
236 toggle_ready_jedec(dst - 1);
241 for (i = 0; i < page_size; i++) {
250 if (!ok && tried++ < MAX_REFLASH_TRIES) {
255 fprintf(stderr, " page %d failed!\n",
256 (unsigned int)(d - bios) / page_size);
261 int write_byte_program_jedec(volatile uint8_t *bios, uint8_t *src,
262 volatile uint8_t *dst)
264 int tried = 0, ok = 1;
266 /* If the data is 0xFF, don't program it */
272 /* Issue JEDEC Byte Program command */
273 *(volatile uint8_t *)(bios + 0x5555) = 0xAA;
274 *(volatile uint8_t *)(bios + 0x2AAA) = 0x55;
275 *(volatile uint8_t *)(bios + 0x5555) = 0xA0;
277 /* transfer data from source to destination */
279 toggle_ready_jedec(bios);
281 if (*dst != *src && tried++ < MAX_REFLASH_TRIES) {
285 if (tried >= MAX_REFLASH_TRIES)
291 int write_sector_jedec(volatile uint8_t *bios, uint8_t *src,
292 volatile uint8_t *dst, unsigned int page_size)
296 for (i = 0; i < page_size; i++) {
297 write_byte_program_jedec(bios, src, dst);
304 int write_jedec(struct flashchip *flash, uint8_t *buf)
307 int total_size = flash->total_size * 1024;
308 int page_size = flash->page_size;
309 volatile uint8_t *bios = flash->virtual_memory;
311 erase_chip_jedec(flash);
312 // dumb check if erase was successful.
313 for (i = 0; i < total_size; i++) {
314 if (bios[i] != (uint8_t) 0xff) {
315 printf("ERASE FAILED @%d, val %02x!\n", i, bios[i]);
320 printf("Programming page: ");
321 for (i = 0; i < total_size / page_size; i++) {
322 printf("%04d at address: 0x%08x", i, i * page_size);
323 write_page_write_jedec(bios, buf + i * page_size,
324 bios + i * page_size, page_size);
325 printf("\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b\b");